CVE-2023-28288
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2023-28288 is a new vulnerability affecting Microsoft SharePoint servers. This spoofing issue allows unauthenticated attackers to manipulate the behavior of a SharePoint site, creating a false sense of authenticity. By carefully crafted URL manipulation, an adversary can trick users into believing they are accessing a legitimate SharePoint page, potentially leading to the disclosure of sensitive information or the execution of malicious code. Microsoft recommends applying the latest security updates to mitigate this risk. This vulnerability underscores the importance of maintaining up-to-date software and being cautious when clicking on suspicious links.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft SharePoint Server
- Microsoft SharePoint Foundation
Affected Vendors
- Microsoft