Web Hack List

Other nomination

SharePoint ToolShell – One Request PreAuth RCE chain CVE-2025-53770

A one-request pre-auth remote code execution chain in SharePoint: a Referer of the SignOut page skips the anonymous-access check, and ToolPane.aspx parses attacker-supplied control markup before the form-digest check. A type-name parsing flaw treats unqualified generic names as object, defeating the deserialization allow-list.

Record

Researcher
@_l0gg and khoadha
Published by
Blog of Viettel Cyber Security
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @_l0gg and khoadha, first published at the original source. Preserved copies are kept so the citation survives its host.