Microsoft SharePoint Spoofing Vulnerability via Cross-Site Scripting
Vulnerability
A cross-site scripting vulnerability has been identified in Microsoft SharePoint Server products, allowing authorized attackers to perform spoofing attacks over the network. This issue arises from improper input neutralization during web page generation, which could be exploited by convincing users to open malicious links.
Impact
Exploitation of this vulnerability could lead to spoofing attacks, allowing an attacker to impersonate another user or entity.
Remediation
Users can download the security update for Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 from the Microsoft Update Catalog. Instructions for downloading the security update are available on the Microsoft Support website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
