A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server

Overview :

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka ‘Microsoft Office SharePoint XSS Vulnerability’. This CVE ID is unique from CVE-2020-0893.

Reference Key :

Each reference used in CVE has the following structure:

SOURCE: NAME

Where possible, the NAME is selected to facilitate searches on a SOURCE’s website. For references that do not have a well-defined identifier, a release date and/or subject header may be included.

Reference Order :

References are typically listed in the order below:

Mitigations :

Microsoft has not identified any mitigating factors for this vulnerability.

Workarounds :

Microsoft has not identified any workarounds for this vulnerability.

FAQ :

Is the Preview Pane an attack vector for this vulnerability?

No, the Preview Pane is not an attack vector.

Acknowledgements :

Huynh Phuoc Hung, @hph0var

See acknowledgements for more information.

Facebook
Twitter
LinkedIn

Recent Blog Posts

Cybersecurity Awareness Month 2025
Layer 7 Attack Recovery Guide Step by Step (2025)
Top 12 Features Every MSSP Needs in a WAAP Platform (2025 Guide)
Top 8 Cybersecurity Challenges Indian Enterprises Face in 2025
Best Tools to Identify Broken Access Control in APIs

WAF Solution