Executive brief
Microsoft Office SharePoint, a widely used platform for document management and team collaboration, is affected by a security vulnerability that could allow an attacker to perform spoofing. An authorized user on the network could trick another user into performing unintended actions or viewing fraudulent content. This could lead to unauthorized access to sensitive information or the disruption of internal business workflows.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An attacker with low-privileged credentials (PR:L) can exploit this over the network by injecting malicious scripts into SharePoint pages. Successful exploitation requires a victim to interact with the affected page (UI:R). This allows the attacker to perform spoofing attacks, potentially leading to unauthorized data disclosure or integrity compromises within the context of the victim's session. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory