Other nomination
Code injection in Workflows leading to SharePoint RCE
SharePoint compiled XOML workflow files without escaping attribute values such as the InterfaceType of CallExternalMethodActivity, writing them straight into generated C# source. Injecting there escapes the generated method and runs arbitrary commands on the server, reachable over the webpartpages SOAP endpoint and fixed as CVE-2020-0646.
Record
- Researcher
- Soroush Dalili
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host.