Impact
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. An attacker who can supply input to a SharePoint page can inject malicious script that runs in the victim’s browser, enabling the attacker to spoof the SharePoint interface or mislead users about content. This issue is classified as CWE‑79 and allows spoofing without requiring authentication.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. No specific patch versions are listed, so all current supported releases of these products remain vulnerable until Microsoft issues a fix.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit the flaw by submitting malicious input through the SharePoint web interface, allowing the injected script to execute in the victim's browser and facilitating spoofing of content over the network. Attack vector is inferred to be the web interface based on the description, and no special privileges are required.
OpenCVE Enrichment