Security researchers discover a bug in Microsoft’s SharePoint connector on Power Platform
A server-side request forgery flaw could have allowed threat actors to steal people’s login credentials
It has been patched, but users should still update as soon as possible
Experts have warned Microsoft’s SharePoint connector on Power Platform was vulnerable to a server-side request forgery (SSRF) flaw which could have allowed threat actors to steal people’s login credentials.
Cybersecurity researchers from Zenity Labs recently detailed their findings in an in-depth technical analysis, explaining how, in essence, threat actors could use the “custom value” feature in a SharePoint connector, which would allow them to add a custom URL in a flow. To do that, they would first need to have access to an Environment Maker role, and the Basic User role, within Power Platform.
+ There are no comments
Add yours