Information disclosure in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2020-16942
Published: October 13, 2020
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. A local administrator can access to the specific SharePoint page and gain unauthorized access to sensitive information on the system.
Affected software
Microsoft SharePoint Server