Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-06-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation, a cross‑site scripting flaw, permits an attacker to inject malicious HTML or script into SharePoint pages. This injection can cause users to view counterfeit pages or messages that appear to originate from legitimate SharePoint sites, effectively enabling spoofing over the network. The vulnerability therefore poses a risk of deception and potential social‑engineering attacks if users act on the forged content.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. All deployments of these releases contain the flaw unless a patch is applied.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity level. The EPSS score of less than 1 % suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploits. The likely attack vector is inferred to be the need for an attacker to supply content that is rendered in a SharePoint page—typically via the web interface or an administrative import—so the vulnerability requires some level of content creation or editing privilege to be exploited.

Generated by OpenCVE AI on July 17, 2026 at 03:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft security update for CVE‑2026‑45465 when it becomes available.
  • Restrict content creation and editing permissions to trusted users or groups to reduce opportunities for malicious input.
  • Implement strict output encoding for all data rendered in SharePoint pages, using Microsoft’s built‑in encoding functions to neutralize script tags.
  • Continuously monitor SharePoint logs for unexpected content injections or abnormal page rendering patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on July 17, 2026 at 03:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Wed, 10 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Wed, 10 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-15T20:09:48.685Z

Reserved: 2026-05-12T16:06:43.098Z

Link: CVE-2026-45465

cve-icon Vulnrichment

Updated: 2026-06-10T14:22:52.692Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T17:17:20.957

Modified: 2026-06-10T20:26:09.490

Link: CVE-2026-45465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T03:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')