Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-06-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation in Microsoft SharePoint leads to cross‑site scripting that can be leveraged by an authorized user to impersonate the site or another user on the network. The spoofing can trick legitimate users into interacting with content they believe originates from a trusted source, potentially enabling social engineering or credential theft. The vulnerability does not grant arbitrary code execution but allows an attacker to subvert user trust within the affected SharePoint environment.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. No additional version details are specified in the CNA information, indicating that all releases of these products could be vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity, and the EPSS score is not available, suggesting limited or unknown public exploitation. The vulnerability requires the attacker to be an authorized user with permission to create or modify content that is rendered in a web page. Because the technique relies on XSS within the application, it can be exploited through normal user interfaces and does not require privilege escalation beyond the authorized account. The vulnerability is not listed in CISA’s KEV catalog, so no known active exploitation campaigns are reported. The risk remains moderate but should be mitigated to prevent potential user deception.

Generated by OpenCVE AI on June 9, 2026 at 19:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Microsoft security updates that address CVE-2026‑45465 as soon as they are released.
  • Restrict content creation and editing rights to trusted users and eliminate unnecessary authorizations that could be used to inject malicious input.
  • Enforce proper output encoding and input validation for all user‑supplied data rendered in SharePoint pages to neutralize cross‑site scripting attempts.
  • Monitor SharePoint applications for unusual authentication or content injection events that could indicate exploitation attempts.

Generated by OpenCVE AI on June 9, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Wed, 10 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-10T17:54:17.238Z

Reserved: 2026-05-12T16:06:43.098Z

Link: CVE-2026-45465

cve-icon Vulnrichment

Updated: 2026-06-10T14:22:52.692Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T17:17:20.957

Modified: 2026-06-10T20:26:09.490

Link: CVE-2026-45465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T21:15:05Z

Weaknesses