Path traversal in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2019-1491
Published: January 7, 2020
Vulnerability identifier: #VU24028
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1491
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request to the SharePoint Server instance and read arbitrary files on the system.
Affected software
Microsoft SharePoint Foundation
Microsoft SharePoint Server
Microsoft SharePoint Server
How to mitigate CVE-2019-1491
Install update from vendor's website.