Unrated severityNVD Advisory· Published Apr 9, 2013· Updated Jun 16, 2026
CVE-2013-1290
CVE-2013-1290
Description
Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:microsoft:sharepoint_server:2013:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:sharepoint_server:2013:*:*:*:*:*:*:*
- (no CPE)range: = 2013
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.