Information disclosure in Microsoft products - CVE-2023-24954
Published: May 9, 2023 / Updated: June 29, 2023
Vulnerability identifier: #VU75908
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-24954
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output within the userphoto endpoint. A remote user can gain unauthorized access to sensitive information on the system.
Affected software
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
How to mitigate CVE-2023-24954
Install updates from vendor's website.