← Back

CVE-2013-1290

nvd nist
Published: Apr 9, 2013Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:P/I:N/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."

Affected (1)

1 product
Sharepoint Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2013

Related CWEs

Timeline

No history available yet.