CVE-2020-16942
MEDIUMMicrosoft SharePoint Server - Information Disclosure via Script Path Rendering
Title source: llmDescription
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page.</p> <p>To take advantage of the vulnerability, an attacker would require access to the specific SharePoint page affected by this vulnerability.</p> <p>The security update addresses the vulnerability by correcting how scripts are referenced on some SharePoint pages.</p>
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16942
Scores
CVSS v3
4.1
EPSS
0.0088
EPSS Percentile
55.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (4)
microsoft/sharepoint_enterprise_server
2016
microsoft/sharepoint_foundation
2010 sp2
microsoft/sharepoint_foundation
2013 sp1
microsoft/sharepoint_server
2019
Published
Oct 16, 2020
Tracked Since
Feb 18, 2026