Executive brief
Microsoft Office SharePoint is a web-based platform used by organizations to store, organize, and share documents and information. This vulnerability allows an authorized user to inject malicious code into web pages, enabling them to spoof content or trick other users into performing unintended actions. While the attacker must already have legitimate access to the system, the attack requires no special technical expertise and could damage user trust or enable social engineering campaigns.
Technical details
This is a cross-site scripting (XSS) vulnerability arising from improper neutralization of user-supplied input during web page generation in Microsoft Office SharePoint. An authorized attacker can inject malicious JavaScript into the application, which is then reflected or stored and executed in the browsers of other users. The attack vector is network-based and requires the attacker to already have valid credentials; no elevation of privileges or special technical preconditions are needed. Successful exploitation allows spoofing of web content and potential session hijacking or credential theft. Microsoft has released a security patch to address this vulnerability.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-08-11: disclosed