Any tier · 20 specialized tests

SharePoint Security (Enterprise)

ViewState deserialisation, auth bypass, RCE chain

What Gets Tested

RCE via ViewState deserialisation (CVE-2019-0604)
Auth bypass (CVE-2023-29357)
RCE chain (CVE-2023-24955)
SPRequestGuid header enumeration
/_layouts/15/ path exposure
ASP.NET ViewState MAC validation
Nuclei sharepoint/ template pack

How It Works

1

Detection

Fingerprint via /_layouts/15/, MicrosoftSharePointTeamServices header, SPRequestGuid.

2

ViewState

Probe ViewState deserialisation + MAC-validation bypass.

3

Known CVEs

Test 2019/2023 chain exploits against server-side handlers.

Compliance Coverage

OWASP-A03 (Injection) OWASP-A06 (Vulnerable Components)

SharePoint Security (Enterprise)

€159

Any tier · One-time per scan

20 specialized tests + AI-powered analysis

Start Your Scan

Select this addon when configuring your scan

Related Add-Ons