Impact
The vulnerability is an improper neutralization of input during web page generation that results in cross‑site scripting, allowing an authorized attacker to forge or alter displayed content and mislead users.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are impacted.
Risk and Exploitability
The CVSS score of 4.6 indicates a moderate severity, and the EPSS score is not available; the vulnerability is not listed in the CISA KEV catalog. An attacker with appropriate authorization can craft input that the Project Server processes and renders, leading to spoofing without requiring additional privileges.
OpenCVE Enrichment