漏洞描述
Detected exposed SharePoint site metadata endpoints.
id: sharepoint-site-metadata-disclosure
info:
name: Microsoft SharePoint - Site Metadata Disclosure
author: 0x_Akoko
severity: low
description: |
Detected exposed SharePoint site metadata endpoints.
reference:
- https://learn.microsoft.com/en-us/sharepoint/dev/sp-add-ins/get-to-know-the-sharepoint-rest-service
- https://medium.com/@ujmalhotra95/tales-of-sharepoint-api-misconfigurations-11073ad384fd
metadata:
max-request: 2
verified: true
shodan-query: http.title:"SharePoint"
fofa-query: title="SharePoint"
tags: sharepoint,microsoft,exposure,misconfig
http:
- method: GET
path:
- "{{BaseURL}}/_api/site"
- "{{BaseURL}}/_api/web"
headers:
Accept: "application/json;odata=verbose"
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains_all(body, "__metadata","WelcomePage") || contains_all(body, "ServerRelativeUrl","Upgrading")'
condition: and
# digest: 4b0a004830460221008ea60e621a759b1df0fbd0e502c2cbd638dfac725f39e1fb01b106fa59e5416502210091d4bafd6b9492fea39787fa269bb04e78a8707110161a50c1670eb214eeb0af:922c64590222798bb761d5b6d8e72950