Web Hack List

Collected research

Code injection in Workflows leading to SharePoint RCE

Code injection in Workflows leading to SharePoint RCE (CVE-2020-0646)

SharePoint compiled XOML workflow files without escaping attribute values such as the InterfaceType of CallExternalMethodActivity, writing them straight into generated C# source. Injecting there escapes the generated method and runs arbitrary commands on the server, reachable over the webpartpages SOAP endpoint and fixed as CVE-2020-0646.

Record

Document
Code injection in Workflows leading to SharePoint RCE (CVE-2020-0646)
Researcher
Soroush Dalili
Published by
mdsec.co.uk
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .