A worrying security defect could have left Microsoft SharePoint users open to attack


  • Security researchers discover an error in Microsoft’s SharePoint connector on the energy platform
  • A falsification failure of the server side could have allowed threat actors to steal the people’s login credentials
  • It has been paved, but users must still be updated as soon as possible

Experts warned that Microsoft’s SharePoint connector on the power platform was vulnerable to a falsification defect of the server’s side (SSRF) that could have allowed threat actors to steal the people’s login credentials of people .

Zenity Labs cybersecurity researchers recently detailed their findings in an in -depth technical analysis, explaining how, in essence, threat actors could use the “personalized value” function in a SharePoint connector, which would allow them to add a personalized URL In a flow. To do that, they would first need to have access to an environment manufacturer role, and the basic role of the user, within the power platform.

Leave a Comment

Your email address will not be published. Required fields are marked *