Impact
This flaw is a cross‑site scripting vulnerability (CWE‑79) that allows an attacker who is already authorized to influence the content of web pages generated by Microsoft SharePoint. By injecting malicious script, the attacker can make the application display forged information, effectively causing users to believe that the content or interactions originate from a trusted source within the organization.
Affected Systems
The vulnerability exists in Microsoft SharePoint Server Subscription Edition. No specific version numbers are provided, so all current releases of that product should be evaluated for the presence of the flaw.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity flaw, while the EPSS score of less than 1% suggests that exploitation is unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an attacker to be authenticated or otherwise authorized within the network, the expected attack vector is internal or privileged. Without a publicly available exploit, the risk remains largely theoretical but could be significant if the attacker succeeds.
OpenCVE Enrichment