CVE-2020-16941 MEDIUM

CVE-2020-16941: Microsoft SharePoint Information Disclosure Vulnerability

Vendor Microsoft
Product Microsoft SharePoint Enterprise Server 2016
Published October 16, 2020
Last update August 4, 2024

CVSS base score

4.1/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

What the vulnerability does

01Description

<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page.</p> <p>To take advantage of the vulnerability, an attacker would require access to the specific SharePoint page affected by this vulnerability.</p> <p>The security update addresses the vulnerability by correcting how scripts are referenced on some SharePoint pages.</p>

Key dates

02Disclosure timeline

October 16, 2020 CVE published
August 4, 2024 Record updated