Input validation error in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2019-1257
Published: September 11, 2019
Microsoft SharePoint Foundation
Microsoft SharePoint Server
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote authenticated attacker with ability to upload a specially crafted SharePoint application package can execute arbitrary code on the system with privileges of the SharePoint server farm account.