Executive brief
Microsoft Office SharePoint is a collaboration platform used to manage documents and content across organizations. A cross-site scripting vulnerability in the web page generation allows an authorized user to inject malicious scripts that could trick other users into performing unwanted actions, such as transferring files, changing permissions, or compromising account credentials through content spoofing.
Technical details
This vulnerability is a stored or reflected cross-site scripting (XSS) flaw in Microsoft Office SharePoint's web page generation mechanism. The root cause is improper neutralization (sanitization) of user-supplied input before rendering it in web pages. An authorized attacker can inject malicious JavaScript code into SharePoint content, which executes in the browsers of other users viewing the affected page. The vulnerability requires authentication and user interaction (visiting the compromised page), enabling spoofing attacks such as credential harvesting or malicious redirects. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-09-08: disclosed