CVE-2020-1439
high · 8.8A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
8.8
CVSS
20.3%
EPSS (exploit prob.)
97th
EPSS percentile
2020-07-14
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | sharepoint_enterprise_server | 2013 |
| microsoft | sharepoint_enterprise_server | 2016 |
| microsoft | sharepoint_foundation | 2013 |
| microsoft | sharepoint_server | 2010 |
| microsoft | sharepoint_server | 2019 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-1439