Executive brief
Microsoft Office SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that could allow an attacker to perform spoofing. By tricking a user into interacting with a malicious link or page, an attacker can execute unauthorized scripts in the user's browser session. This could lead to the unauthorized access of sensitive information or the performance of actions on behalf of the user within the SharePoint environment.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An attacker can exploit this by sending a specially crafted request to a vulnerable SharePoint server. The attack requires user interaction, typically involving a victim clicking a malicious link. Successful exploitation allows the attacker to perform spoofing and execute arbitrary script code in the context of the victim's browser, potentially leading to information disclosure or session hijacking. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.
- 2026-06-09: patched: Security updates made available via Microsoft Update Guide.