Impact
Improper neutralization of input during web page generation, a cross‑site scripting flaw, permits an attacker to inject malicious HTML or script into SharePoint pages. This injection can cause users to view counterfeit pages or messages that appear to originate from legitimate SharePoint sites, effectively enabling spoofing over the network. The vulnerability therefore poses a risk of deception and potential social‑engineering attacks if users act on the forged content.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. All deployments of these releases contain the flaw unless a patch is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity level. The EPSS score of less than 1 % suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploits. The likely attack vector is inferred to be the need for an attacker to supply content that is rendered in a SharePoint page—typically via the web interface or an administrative import—so the vulnerability requires some level of content creation or editing privilege to be exploited.
OpenCVE Enrichment