Executive brief
Microsoft Office SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that could allow an attacker to perform spoofing. An authorized user on the network could trick another user into executing malicious scripts within their browser session. This could lead to unauthorized actions being performed on behalf of the victim or the exposure of sensitive information within the SharePoint environment.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An authenticated attacker with low privileges can exploit this by injecting malicious scripts into a SharePoint page. The attack requires a victim to interact with the affected page (User Interaction: Required). Successful exploitation allows the attacker to perform spoofing, potentially leading to the disclosure of sensitive information or unauthorized modifications within the context of the victim's session. The vulnerability is tracked as CVE-2026-48562 and has a CVSS 3.1 base score of 4.6.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory