A worrying security flaw could have left Microsoft SharePoint users open to attack

Estimated read time 2 min read




  • Security researchers discover a bug in Microsoft’s SharePoint connector on Power Platform
  • A server-side request forgery flaw could have allowed threat actors to steal people’s login credentials
  • It has been patched, but users should still update as soon as possible

Experts have warned Microsoft’s SharePoint connector on Power Platform was vulnerable to a server-side request forgery (SSRF) flaw which could have allowed threat actors to steal people’s login credentials.

Cybersecurity researchers from Zenity Labs recently detailed their findings in an in-depth technical analysis, explaining how, in essence, threat actors could use the “custom value” feature in a SharePoint connector, which would allow them to add a custom URL in a flow. To do that, they would first need to have access to an Environment Maker role, and the Basic User role, within Power Platform.



Source link

You May Also Like

More From Author

+ There are no comments

Add yours