Published: 10/01/2018 Updated: 29/01/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability".

Affected Products

Vendor Product Versions
MicrosoftSharepoint Enterprise Server2013, 2016

Github Repositories

TODO: Fix -p flag -c flag is deprecated CVE Watcher queries the National Vulnerability Database (NVD) for CVEs related to specific vendor and/or product Example(s): python CVEWatcherpy -v Microsoft -s 0 -S 2015 -e 0 -E 2015 python CVEWatcherpy -v Adobe -s 0 -S 2015 -e 0 -E 2015 python CVEWatcherpy -v Google -p chrome -s 4 -S 2014 -e 11 -E 2014 Example Output: Microsoft,78,H