Impact
The vulnerability is a cross‑site scripting flaw arising from insufficient neutralization of user input in SharePoint web page generation. This flaw allows an unauthenticated attacker to inject malicious code that browsers render as part of legitimate SharePoint pages, enabling them to spoof the appearance or identity of the site. The attacker can thereby deceive visitors, potentially facilitating phishing or defacement. No remote code execution is possible; the impact is confined to the web‑application layer and the integrity of the site’s content.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are all affected. Any installation of these product lines, regardless of service pack or patch level, remains vulnerable until a Microsoft update is applied.
Risk and Exploitability
The CVSS score of 5.4 marks the vulnerability as moderate. The EPSS score of less than 1% indicates a low, but non‑zero, likelihood of exploitation in the wild. The flaw can be triggered by an unauthorized attacker who supplies malicious input to a vulnerable part of the SharePoint site; the exact attack vector is not detailed but is inferred to involve publicly accessible input that is not properly sanitized. Once the injection succeeds, every user that renders the affected page will experience the spoofed content. Because the vulnerability is purely a web‑application issue, it does not expose the server to arbitrary code execution, but it can support broader social‑engineering attacks such as credential harvesting. Microsoft has not catalogued this vulnerability in the CISA KEV database.
OpenCVE Enrichment