Executive brief
Microsoft Office SharePoint, a widely used platform for document management and team collaboration, is affected by a security vulnerability that could allow an attacker to perform spoofing. By tricking a user into interacting with a malicious link or page, an authorized attacker can execute unauthorized scripts in the victim's browser session. This could lead to the unauthorized access of sensitive information or the performance of actions on behalf of the user within the SharePoint environment.
Technical details
A stored or reflected cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An attacker with basic user privileges (PR:L) can exploit this by sending a specially crafted request to a SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page (UI:R). Once executed, the attacker can perform spoofing attacks, potentially hijacking user sessions or accessing data within the context of the affected user. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory