CVE-2018-8578: Microsoft SharePoint Enterprise Server

Medium severity, CVSS 4.3. EPSS: 4.9% chance of exploitation in the next 30 days.

An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.

Affected products

  • Microsoft SharePoint Enterprise Server: version 2013 only

Published 2018-11-14. Last modified 2026-06-17.