PT-2026-68840 · Microsoft · Sharepoint Server
CVE-2026-70332
·
Published
2026-08-06
·
Updated
2026-08-07
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office SharePoint (affected versions not specified)
Description
Microsoft Office SharePoint contains issues related to improper neutralization of input during web page generation, leading to cross-site scripting (XSS), and server-side request forgery (SSRF). These flaws allow an unauthorized attacker to perform spoofing over a network. Cross-site scripting is a technique where malicious scripts are injected into trusted websites, and server-side request forgery is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sharepoint Server