<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cross-Site-Scripting on Aretiq AI</title><link>https://aretiq.ai/tags/cross-site-scripting/</link><description>Recent content in Cross-Site-Scripting on Aretiq AI</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 16 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://aretiq.ai/tags/cross-site-scripting/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-45453 — Microsoft SharePoint Server Workflow Pages DocURL Parameter Reflected Cross-Site Scripting</title><link>https://aretiq.ai/research/vul260604-cve-2026-45453-microsoft-sharepoint-server-workflow-pages-docurl-parameter-reflected-cross-site-scripting/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/research/vul260604-cve-2026-45453-microsoft-sharepoint-server-workflow-pages-docurl-parameter-reflected-cross-site-scripting/</guid><description>&lt;h2 id="1-overview">1. Overview&lt;/h2>
&lt;p>A reflected cross-site scripting vulnerability exists in three SharePoint Server workflow management pages. The &lt;code>DocURL&lt;/code> query string parameter is rendered directly into HTML anchor tag &lt;code>href&lt;/code> attributes without any encoding, allowing an attacker to inject arbitrary HTML attributes including JavaScript event handlers. An unauthenticated attacker can craft a malicious URL and deliver it to an authenticated SharePoint user; when the victim visits the link and hovers over the page&amp;rsquo;s tab navigation, the injected JavaScript executes in the SharePoint origin context, enabling session hijacking and unauthorized actions. Microsoft addressed this vulnerability in the June 2026 security update (KB5002880 for SharePoint Server 2016, KB5002874 for SharePoint Server 2019).&lt;/p></description></item></channel></rss>