Impact
The vulnerability is a cross‑site scripting flaw caused by improper neutralization of input during web page generation in Microsoft Office SharePoint, allowing an unauthorized attacker to inject malicious content that browsers render as part of legitimate SharePoint pages, leading to spoofing over a network. This flaw is confined to the presentation layer – it does not allow code execution on the server or alteration of data. Consequently, the primary threat is phishing or defacement via spoofed content, but remote code execution is not possible.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are all affected. Any installation of these product lines, regardless of service pack or patch level, remains vulnerable until a Microsoft update is applied.
Risk and Exploitability
The CVSS score of 5.4 marks the vulnerability as moderate. The EPSS score of less than 1% indicates a low, but non‑zero, likelihood of exploitation in the wild. The flaw allows an unauthorized attacker to inject malicious content during page generation because input is not properly neutralized, and the resulting spoofed content will be rendered by any user visiting the affected page. Once the injection succeeds, every user that renders the affected page will experience the spoofed content. Because the vulnerability is purely a web‑application issue, it does not expose the server to arbitrary code execution, but it can support broader social‑engineering attacks such as credential harvesting. Microsoft has not catalogued this vulnerability in the CISA KEV database.
OpenCVE Enrichment