CVE-2020-16941

MEDIUM

Microsoft SharePoint Server - Information Disclosure via Script Path Rendering

Title source: llm
STIX 2.1

Description

<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page.</p> <p>To take advantage of the vulnerability, an attacker would require access to the specific SharePoint page affected by this vulnerability.</p> <p>The security update addresses the vulnerability by correcting how scripts are referenced on some SharePoint pages.</p>

References (1)

Core 1
Core References

Scores

CVSS v3 4.1
EPSS 0.0090
EPSS Percentile 55.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (4)
microsoft/sharepoint_enterprise_server 2016
microsoft/sharepoint_foundation 2010 sp2
microsoft/sharepoint_foundation 2013 sp1
microsoft/sharepoint_server 2019
Published Oct 16, 2020
Tracked Since Feb 18, 2026