CVE-2015-6117: Microsoft SharePoint Foundation

Medium severity, CVSS 6.1. EPSS: 6.9% chance of exploitation in the next 30 days.

Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2016-0011.

Affected products

  • Microsoft SharePoint Foundation: version 2013 only
  • Microsoft SharePoint Server: version 2013 only

Published 2016-01-13. Last modified 2026-06-17.