Microsoft SharePoint Remote Code Execution Vulnerability
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31181 | patch vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-573/ | third party advisory vdb entry |
http://packetstormsecurity.com/files/163208/Microsoft-SharePoint-Unsafe-Control-And-ViewState-Remote-Code-Execution.html | third party advisory vdb entry exploit |
https://packetstorm.news/files/id/163208 |