Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-45453 — Microsoft SharePoint Server Workflow Pages DocURL Parameter Reflected Cross-Site Scripting

Summary

CVE-2026-45453: reflected XSS in three SharePoint workflow pages—DocURL is written unencoded into href attributes, executing on hover and enabling session hijacking; fixed in June 2026.
CVE
CVE-2026-45453
Published
Collected

original ↗