Executive brief
Microsoft Office SharePoint, a widely used collaboration and document management platform, contains a security vulnerability that could allow an attacker to perform spoofing attacks. By tricking a user into interacting with a malicious link or page, an authorized attacker can execute unauthorized scripts in the victim's browser session. This could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user within the SharePoint environment.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation. An attacker with basic user privileges (PR:L) can exploit this by sending a specially crafted request to a SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page (UI:R). This allows the attacker to execute arbitrary script in the context of the victim's browser, potentially leading to session hijacking or unauthorized data access. The vulnerability is tracked as CWE-74/CWE-79 and has a CVSS 3.1 score of 7.3.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.