Impact
The flaw consists of improper neutralization of user‑supplied input during web page generation in Microsoft Office SharePoint. A remote attacker who does not require prior authentication can exploit this cross‑site scripting vulnerability to inject crafted content that mimics legitimate interface elements, effectively performing spoofing over a network.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are impacted. The CNA does not specify individual sub‑versions, so any installation of these editions vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, while the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and no widely known exploitation to date is reported. The likely attack vector is remote.
OpenCVE Enrichment