Executive brief
Microsoft Office SharePoint is a collaboration platform used to manage documents and content across organizations. A cross-site scripting (XSS) vulnerability allows authorized users to inject malicious scripts that execute in other users' browsers, enabling account spoofing, credential theft, or unauthorized actions on behalf of legitimate users.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint resulting from improper neutralization of user input during web page generation. An authorized attacker can inject malicious scripts through SharePoint's interface, which are then executed in the browsers of other users viewing the affected content. The vulnerability requires authentication to exploit and allows an attacker to perform spoofing attacks or redirect users to malicious sites. Patches are available from Microsoft.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-08-11: disclosed