Top 5 This Week

Related Posts

A worrying security flaw could have left Microsoft SharePoint users open to attack


  • Security researchers discover a bug in Microsoft’s SharePoint connector on Power Platform
  • A server-side request forgery flaw could have allowed threat actors to steal people’s login credentials
  • It has been patched, but users should still update as soon as possible

Experts have warned Microsoft’s SharePoint connector on Power Platform was vulnerable to a server-side request forgery (SSRF) flaw which could have allowed threat actors to steal people’s login credentials.

Cybersecurity researchers from Zenity Labs recently detailed their findings in an in-depth technical analysis, explaining how, in essence, threat actors could use the “custom value” feature in a SharePoint connector, which would allow them to add a custom URL in a flow. To do that, they would first need to have access to an Environment Maker role, and the Basic User role, within Power Platform.

source: https://www.techradar.com/pro/security/a-worrying-security-flaw-could-have-left-microsoft-sharepoint-users-open-to-attack

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Popular Articles