Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
How could an attacker exploit this vulnerability? An attacker could send a specially crafted URL to an authenticated SharePoint user and persuade them to visit it and submit the form. Successful exploitation could allow the attacker to run script in the user's SharePoint session, potentially accessing information or modifying site content.
Bui Xuan Quang (buxu) with Ncsgroup.vn, <a href="https://smlijun.github.io/">DongJun Kim</a> with UIUC, <a href="https://hwiwonl.ee/">Hwiwon Lee (hwiwonl)</a> with UIUC, <a href="https://nevul37.github.io/">Jongseong Kim (nevul37)</a> with UIUC