Impact
Microsoft SharePoint is vulnerable to a cross‑site scripting flaw caused by improper neutralization of input during web page generation, allowing an unauthorized attacker to perform spoofing over a network. An unauthorized attacker can embed malicious or forged content, leading to spoofed web pages being presented to users over the network. This vulnerability enables attackers to deceive users through phishing or social‑engineering attacks.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. All deployments of these releases contain the flaw unless a patch is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity level. The EPSS score of less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploits. The likely attack vector is inferred to be the need for an attacker to supply content that is rendered in a SharePoint page—typically via the web interface or an administrative import—so the vulnerability requires some level of content creation or editing privilege to be exploited.
OpenCVE Enrichment