Most SharePoint Installations Vulnerable to XSS Attacks
One of the vulnerabilities patched by Microsoft this week with its monthly security updates is a potentially serious cross-site scripting (XSS) flaw believed to affect most SharePoint 2016 installations.
Read more: Most SharePoint Installations Vulnerable to XSS Attacks
Story added 15. June 2017, content source with full text you can find at link above.