A researcher on Wednesday reported that he had found a vulnerability in the “sticker” feature in Microsoft Teams that could let actors conduct cross-site scripting (XSS) attacks. In a blog post, Numan Turle, a researcher from Gais Cyber Security, reported that he initially found CVE-2021-24114 last year, which was found to trigger an account takeover vulnerability in Teams iOS.
Link: Researcher finds vulnerability in Microsoft Teams that could have led to XSS attacks
via http://www.scmagazine.com