Executive brief
Microsoft Office SharePoint contains a cross-site scripting (XSS) vulnerability in web page generation that allows authorized attackers to perform spoofing attacks. An authenticated user could craft malicious input that executes unintended actions or displays fake content to other users, potentially leading to credential theft or unauthorized transactions.
Technical details
This is an improper input neutralization vulnerability (CWE-79: Improper Neutralization of Input During Web Page Generation) affecting Microsoft Office SharePoint. The vulnerability requires an authenticated attacker with existing access to the SharePoint environment to inject malicious scripts into web page inputs. The injected script executes in the context of other users' browsers, enabling spoofing and social engineering attacks. The attack vector is network-based and requires user interaction (an authenticated user must submit the malicious input and another user must visit the affected page). No public exploit code has been reported in the wild as of the advisory publication date.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-09-08: disclosed