Executive brief
Microsoft Office SharePoint is a widely-used document collaboration and content management platform. This vulnerability allows an authorized user to inject malicious scripts into SharePoint pages, which could be used to impersonate other users, steal credentials, or redirect users to malicious sites. An attacker would need valid SharePoint access to exploit this flaw.
Technical details
This is a cross-site scripting (XSS) vulnerability caused by improper neutralization of user-supplied input during web page generation in Microsoft Office SharePoint. The vulnerability requires an authenticated attacker with authorization to interact with SharePoint. By injecting malicious scripts through vulnerable input fields, an attacker can execute arbitrary JavaScript in the context of other users' browsers, enabling spoofing, session hijacking, or credential theft. A patch is expected from Microsoft.
Affected products
- Microsoft Office SharePoint <UNKNOWN>
Timeline
- 2026-08-11: disclosed