Exploit for #VU29836 XML injection in Microsoft Server applications


Published: 2020-07-30 | Updated: 2021-11-25

Vulnerability identifier: #VU29836

Vulnerability risk: High

CVSSv3.1: 9.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C]

CVE-ID: CVE-2020-1147

CWE-ID: CWE-91

Exploitation vector: Network

Exploits in database: 3

Impact: Code execution

Vulnerable software:
Microsoft SharePoint Server
Server applications / Application servers
Visual Studio
Universal components / Libraries / Software for developers
ASP.NET Core MVC
Universal components / Libraries / Software for developers
Microsoft .NET Core
Server applications / Frameworks for developing and running applications
Microsoft .NET Framework
Server applications / Frameworks for developing and running applications

Vendor: Microsoft