Record summary

CVE-2021-31950 has a selected CVSS score of 7.6 (high); EIP currently links 1 catalogued exploit.

Description

Microsoft SharePoint Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-31948, CVE-2021-31964.

Description source: GitHub Advisory

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

3
ProductSourceVersion rangeStatus

Microsoft SharePoint Enterprise Server 2016

Browse Microsoft / Microsoft SharePoint Enterprise Server 2016
CVE List16.0.0 to < 16.0.5173.1000affected

Microsoft SharePoint Foundation 2013 Service Pack 1

Browse Microsoft / Microsoft SharePoint Foundation 2013 Service Pack 1
CVE List15.0.0 to < 15.0.5353.1000affected
CVE List16.0.0 to < 16.0.10375.20000affected

Proofs of concept

1

Catalogued exploits

ExploitDBMicrosoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forgery (SSRF)ExploitDB exploitby Alex BirnbergNot analyzed1 file
ExploitDB

PoC details

References

3