More

    A worrying security flaw could have left Microsoft SharePoint users open to attack




    • Security researchers discover a bug in Microsoft’s SharePoint connector on Power Platform
    • A server-side request forgery flaw could have allowed threat actors to steal people’s login credentials
    • It has been patched, but users should still update as soon as possible

    Experts have warned Microsoft’s SharePoint connector on Power Platform was vulnerable to a server-side request forgery (SSRF) flaw which could have allowed threat actors to steal people’s login credentials.

    Cybersecurity researchers from Zenity Labs recently detailed their findings in an in-depth technical analysis, explaining how, in essence, threat actors could use the “custom value” feature in a SharePoint connector, which would allow them to add a custom URL in a flow. To do that, they would first need to have access to an Environment Maker role, and the Basic User role, within Power Platform.

    https://cdn.mos.cms.futurecdn.net/GECPn964KJunKWgRJ5mMti-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img