Microsoft SharePoint Server Cross-Site Scripting Vulnerability Allowing Spoofing

Vulnerability

A cross-site scripting vulnerability has been identified in Microsoft SharePoint Server Subscription Edition. This issue arises from improper input neutralization during web page generation, allowing an authorized attacker to perform spoofing over the network. Exploitation of this vulnerability could enable the attacker to execute scripts in the context of the current user by persuading them to click a link, thereby launching a cross-site scripting attack on the SharePoint Server.

Impact

Exploitation of this vulnerability could lead to spoofing attacks, allowing an attacker to impersonate a user or entity.

Remediation

Users can download the security update for Microsoft SharePoint Server Subscription Edition from the Microsoft Update Catalog. Knowledge Base Article 5002815 provides additional information.

Added: Dec 10, 2025, 12:59 AM
Updated: Dec 10, 2025, 12:59 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.0
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.