Executive brief
Microsoft Office SharePoint, a widely used collaboration and document management platform, contains a security vulnerability that could allow an attacker to perform spoofing attacks. By tricking a user into interacting with a malicious link or page, an attacker with basic user permissions could execute unauthorized scripts in the victim's browser. This could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user within the SharePoint environment.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation. An authenticated attacker with low privileges (PR:L) can exploit this vulnerability by sending a specially crafted request to a SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page (UI:R). The vulnerability allows the attacker to execute arbitrary script in the context of the victim's browser, potentially leading to information disclosure or unauthorized data modification. Microsoft has classified this as a spoofing vulnerability with a CVSS 3.1 base score of 4.6.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.