Description


Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Related CPE's


a

microsoft

sharepoint_server

3

Weaknesses



CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-13T18:16:22.167Z

3 days ago

Last modified

2026-01-16T16:17:12.343Z

2 hours ago