Impact
The vulnerability is caused by improper neutralization of special elements in the output that is forwarded to a downstream component in Microsoft Office SharePoint. An authorized attacker with content‑editing rights can inject malicious content that will be displayed as if it originated from a trusted source, allowing spoofing over the network.
Affected Systems
Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition are vulnerable considered at risk until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 7.3 reflects a high severity for compromised SharePoint usage. The EPSS score of < 1% indicates a very low probability that this flaw will be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred from the description: it requires an authenticated SharePoint user with content‑editing rights to inject malicious content that will be displayed to other users, leading to spoofing over the network.
OpenCVE Enrichment