CVE-2017-0107: Microsoft SharePoint Foundation

Medium severity, CVSS 6.1. EPSS: 7% chance of exploitation in the next 30 days.

Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability."

Affected products

  • Microsoft SharePoint Foundation: version 2013 only

Published 2017-03-17. Last modified 2026-06-17.