Executive brief
Microsoft Office SharePoint, a widely used platform for document management and team collaboration, is affected by a security vulnerability that could allow an attacker to perform spoofing. By tricking a user into interacting with a malicious link or page, an authorized attacker can execute unauthorized scripts in the victim's browser. This could lead to the unauthorized access of sensitive information or the performance of actions on behalf of the user within the SharePoint environment.
Technical details
A stored or reflected cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation. An attacker with basic user privileges (PR:L) can exploit this by sending a specially crafted request to a SharePoint server or tricking a victim into clicking a malicious link (UI:R). Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data modification. The vulnerability is tracked as CWE-79 and has a CVSS 3.1 base score of 4.6.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory