CyberRota Analysis
AI-GeneratedMicrosoft Office SharePoint is vulnerable to cross-site scripting due to improper input neutralization during web page generation, enabling authorized attackers to execute spoofing attacks over the network. This could lead to unauthorized access or manipulation of user data. Organizations using SharePoint should prioritize addressing this vulnerability to mitigate potential risks to their data integrity and user trust.
CVE
CVE-2026-55020
Severity
MEDIUM
CVSS
4.6
EPSS
0.41%
Microsoft SharePoint Office
Original NVD Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Related CVEs
Other vulnerabilities affecting the same vendor(s)