VDB
CVE-2023-28288
CVE-2023-28288
PUBLISHED
CVSS 8.100000381469727 HIGH
Microsoft SharePoint Server Spoofing Vulnerability
EPSS 9.09% · 92.8th percentile
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
EPSS Score
9.09%
92.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft SharePoint Server Subscription Edition | 16.0.0, 16.0.0 |
| Microsoft | Microsoft SharePoint Foundation 2013 Service Pack 1 | 15.0.0, 15.0.0 |
| Microsoft | Microsoft SharePoint Enterprise Server 2013 Service Pack 1 | 15.0.0, 15.0.0 |
| microsoft | sharepoint_server | 2019, 2013, 2016 |
| Microsoft | Microsoft SharePoint Server 2019 | 16.0.0, 16.0.0 |
| microsoft | sharepoint_foundation | 2013, 2013, 2013 |
| Microsoft | Microsoft SharePoint Enterprise Server 2016 | 16.0.0, 16.0.0 |
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- http://packetstormsecurity.com/files/173126/Microsoft-SharePoint-Enterprise-Server-2016-Spoofing.html (circl)
- Microsoft SharePoint Server Spoofing Vulnerability (circl)
- Microsoft SharePoint Enterprise Server 2016 - Spoofing (webapps) by Amirhossein Bahramizadeh (coalition_cess)
- Microsoft SharePoint Enterprise Server 2016 - Spoofing Exploit (0day-today)
- Microsoft SharePoint Enterprise Server 2016 - Spoofing Exploit (0day-today)
- Microsoft SharePoint Enterprise Server 2016 - Spoofing Exploit (0day-today)
Timeline
- Apr 11, 2023 CVE Published
- Apr 12, 2023 EPSS Score
- May 20, 2023 EPSS Score
- Jun 26, 2023 PoC Published
- Aug 3, 2023 EPSS Score
- Sep 10, 2023 EPSS Score
- Nov 24, 2023 EPSS Score
- Jan 1, 2024 EPSS Score
- Feb 8, 2024 EPSS Score
- Apr 23, 2024 EPSS Score
- May 31, 2024 EPSS Score
- Aug 14, 2024 EPSS Score