Executive brief
Microsoft Office SharePoint, a widely-used enterprise content management and collaboration platform, contains a cross-site scripting (XSS) vulnerability that allows authorized users to inject malicious scripts. An attacker with valid access could use this flaw to perform spoofing attacks, potentially redirecting users to fraudulent pages or stealing sensitive information, affecting user trust and data integrity.
Technical details
This is a reflected or stored cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint's web page generation functionality. The vulnerability stems from improper input sanitization or output encoding when processing user-supplied data during page rendering. An authorized attacker can inject malicious script code that executes in the context of other users' browsers when they view affected pages. The attack requires prior authentication and user interaction (visiting a crafted link or page). Patches are expected to be available through Microsoft Security Updates.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-08-11: disclosed