CVE-2026-45453 — Microsoft SharePoint Server Workflow Pages DocURL Parameter Reflected Cross-Site Scripting
aretiq.ai | research | CVE-2026-45453 | #appsec | #vulnerability-research | #xss | #sharepoint | #session-hijacking | #reflected-xss | #cve-2026-45453 | #input-encoding
Summary
CVE-2026-45453: reflected XSS in three SharePoint workflow pages—DocURL is written unencoded into href attributes, executing on hover and enabling session hijacking; fixed in June 2026.
- CVE
- CVE-2026-45453
- Published
- Collected
Skip to content