Web Hack List

Collected research

SharePoint ToolShell – One Request PreAuth RCE chain CVE-2025-53770

A one-request pre-auth remote code execution chain in SharePoint: a Referer of the SignOut page skips the anonymous-access check, and ToolPane.aspx parses attacker-supplied control markup before the form-digest check. A type-name parsing flaw treats unqualified generic names as object, defeating the deserialization allow-list.

Record

Researcher
@_l0gg and khoadha
Published by
Blog of Viettel Cyber Security
Date
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @_l0gg and khoadha, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .