Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: Sharepoint XSS Vulnerability - SANS Internet Storm Center SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Sharepoint XSS Vulnerability

Microsoft published KB article #983438 late yesterday, with details about a XSS vulnerability within a SharePoint site. This vulnerability may be used to elevate privileges in Sharepoint. SharePoint Services 3.0 and SharePoint 2007 are affected.

Microsoft notes that the vulnerability is harder to exploit if Internet Explorer 8's built in XSS filter is used by administrators of the site. Another action that may help to mitigate the problem is to restrict access to the vulnerable Help.aspx file. With SharePoint using "httponly" cookies, the impact of the vulnerability is somewhat limited.



Johannes B. Ullrich, Ph.D.
SANS Technology Institute

I will be teaching next: Application Security: Securing Web Apps, APIs, and Microservices - SANS Cyber Defence Japan August 2022


4511 Posts
ISC Handler
Apr 30th 2010

Sign Up for Free or Log In to start participating in the conversation!