Microsoft Office Project Server Cross-Site Scripting Vulnerability Allowing Spoofing

Vulnerability

A cross-site scripting vulnerability has been identified in Microsoft Office Project Server. This issue allows an authorized attacker to perform spoofing over a network by improperly neutralizing input during web page generation. The vulnerability affects several versions of Microsoft SharePoint, including SharePoint Server 2019, SharePoint Enterprise Server 2016, and SharePoint Server Subscription Edition.

Impact

Exploitation of this vulnerability could lead to spoofing attacks, allowing an attacker to impersonate another user or entity.

Remediation

Users can download the security update for Microsoft SharePoint Server 2019, SharePoint Enterprise Server 2016, or SharePoint Server Subscription Edition from the Microsoft Update Catalog.

Added: Jun 9, 2026, 6:45 PM
Updated: Jun 9, 2026, 6:45 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
1.7
exploitability
5.8
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.