Impact
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. The flaw arises because the system fails to sanitize particular special elements before rendering them, enabling a user with the necessary SharePoint privileges to inject malicious content that will be displayed as if it originated from a trusted source. The result is the attacker’s ability to masquerade as another user or entity within the SharePoint environment, creating opportunities for misattribution and higher social engineering risk.
Affected Systems
Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition are vulnerable and considered at risk until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 7.3 reflects a high severity for compromised SharePoint usage. The EPSS score of < 1% indicates a very low probability that this flaw will be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred from the description: it requires an authenticated SharePoint user with sufficient privileges to inject malicious content that will be displayed to others, resulting in spoofing over the network.
OpenCVE Enrichment