Web Hack List

Other nomination

Code injection in Workflows leading to SharePoint RCE

SharePoint compiled XOML workflow files without escaping attribute values such as the InterfaceType of CallExternalMethodActivity, writing them straight into generated C# source. Injecting there escapes the generated method and runs arbitrary commands on the server, reachable over the webpartpages SOAP endpoint and fixed as CVE-2020-0646.

Record

Researcher
Soroush Dalili

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host.