Impact
Improper neutralization of input during web page generation in Microsoft SharePoint (cross‑site scripting) enables an unauthorized attacker to perform spoofing over a network. By injecting malicious code into a SharePoint page, the attacker can cause it to run in the victim’s browser, potentially presenting false or manipulated content and undermining the integrity of the SharePoint interface. This flaw is classified as CWE‑79.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. No specific patch versions are listed, so all current supported releases of these products remain vulnerable until Microsoft issues a fix.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit the flaw by submitting malicious input through the SharePoint web interface, allowing the injected script to execute in the victim's browser and facilitating spoofing of content over the network. Attack vector is inferred to be the web interface based on the description, and no special privileges are required.
OpenCVE Enrichment