Microsoft SharePoint Spoofing Vulnerability via Cross-Site Scripting

Vulnerability

A cross-site scripting vulnerability has been identified in Microsoft Office SharePoint, allowing an authorized attacker to perform spoofing over the network. This issue arises from improper neutralization of input during web page generation.

Impact

Exploitation of this vulnerability could lead to spoofing attacks, allowing an attacker to impersonate another user or entity.

Remediation

Users can download the security update for Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, or SharePoint Enterprise Server 2016 from the Microsoft Update Catalog. Knowledge Base articles are also available for each version.

Added: Apr 14, 2026, 11:05 PM
Updated: Apr 14, 2026, 11:05 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
1.7
exploitability
4.6
remediation
7.7
relevance
5.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.