漏洞描述 Microsoft SharePoint 是美国微软(Microsoft)公司的一套企业业务协作平台。该平台用于对业务信息进行整合,并能够共享工作、与他人协同工作、组织项目和工作组、搜索人员和信息。Microsoft SharePoint 认证接口存在权限绕过漏洞,攻击者可以通过绕过安全机制,获取管理员权限,接管系统后台,恶意执行代码、写入后门、读取敏感文件,从而导致服务器受到攻击并被控制。
相关漏洞推荐 POC CVE-2020-20627: GiveWP - Missing Authorization to Settings Update POC CVE-2023-37999: HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation POC sharepoint-lists-api-disclosure: Microsoft SharePoint - List API Disclosure POC sharepoint-layouts-disclosure: Microsoft SharePoint - Layouts Disclosure POC sharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page Disclosure POC sharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata Disclosure POC sharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages Disclosure POC CVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass (CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行 Microsoft Web Deploy 需授权 反序列化漏洞 可导致任意代码执行 POC CVE-2019-0604: Microsoft SharePoint - Remote Code Execution POC CVE-2020-0646: Microsoft .NET Framework - Remote Code Execution POC CVE-2025-29927-HEADLESS: Next.js Middleware Authorization Bypass