National Cyber Warfare Foundation (NCWF)

Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access Even When Uploading Just One File


0 user ratings
2025-05-28 15:05:30
milo
Blue Team (CND)
Cybersecurity researchers have discovered a security flaw in Microsoft's OneDrive File Picker that, if successfully exploited, could allow websites to access a user's entire cloud storage content, as opposed to just the files selected for upload via the tool.
"This stems from overly broad OAuth scopes and misleading consent screens that fail to clearly explain the extent of access being granted,



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/05/microsoft-onedrive-file-picker-flaw.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.