Executive brief
Microsoft Office Project Server, a platform used by organizations to manage projects and collaborate on tasks, is affected by a security vulnerability. An authorized user on the network could exploit this flaw to perform spoofing or execute malicious scripts in the context of another user's session. This could lead to unauthorized actions being performed on behalf of legitimate users or the theft of sensitive session information.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Office Project Server due to improper neutralization of input during web page generation (CWE-79). An attacker with low-privileged credentials can exploit this vulnerability over the network by tricking a victim into interacting with a malicious link or page. Successful exploitation allows the attacker to execute arbitrary script in the victim's browser session, potentially leading to session hijacking or unauthorized data modification. The vulnerability has a CVSS score of 4.6, reflecting the requirement for user interaction and authenticated access.
Affected products
- Microsoft Office Project Server
Timeline
- 2026-06-09: disclosed: Initial disclosure by Microsoft and NVD publication.