RULE(RULE ID:320701)

Rule General Information
Release Date: 2018-03-19
Rule Name: EXPLOIT Microsoft SharePoint Cross-site Scripting Vulnerability (CVE-2017-8514)
Severity:
CVE ID:
Rule Protection Details
Description: An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint Reflective XSS Vulnerability".
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:98831
SecurityTrackerID:1038663
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8514
Solutions
Microsoft has released a patch on the website. For more information, please visit:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8514