CVE Database
/

CVE-2017-11876

Back to search

CVE-2017-11876

Published: Nov 15, 2017

Modified: Sep 17, 2024

PUBLISHED

Description

Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, such as change permissions and delete content, and inject malicious content in the browser of the victim, aka "Microsoft Project Server Elevation of Privilege Vulnerability".

VendorProductVersions

Microsoft Corporation

Microsoft Server

affected
Microsoft Project Server 2013, Microsoft SharePoint Enterprise Server 2016

References

1039789
vdb-entry
x_refsource_SECTRACK
1039788
vdb-entry
x_refsource_SECTRACK
101754
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now