Input validation error in Microsoft SharePoint Server - CVE-2020-16952
Published: October 13, 2020 / Updated: April 29, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the Microsoft SharePoint fails to check the source markup of an application package. A remote attacker can upload a specially crafted SharePoint application package and execute arbitrary code on the system.
Affected software
How to mitigate CVE-2020-16952
Links to Public Exploits and PoC-codes
- Exploit #9761 - Input validation error (April 29, 2024)
- Exploit #9760 - Input validation error (April 28, 2024)
- Exploit #4745 - Input validation error (October 27, 2020)
- Exploit #4722 - Microsoft SharePoint Server-Side Include and ViewState RCE (October 19, 2020)
- Exploit #4720 - Microsoft SharePoint Server DataFormWebPart CreateChildControls Server-Side Include Remote Code Execution Vulnerability (October 19, 2020)