Impact
Improper neutralization of input during web page generation (cross‑site scripting) in Microsoft Office SharePoint permits an attacker without prior privileges to submit malicious page, enabling them to display spoofed or deceptive information to users who view the page.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected by the XSS flaw. Version information for specific affected revisions is not provided in the CVE; apply any available vendor updates to mitigate the vulnerability.
Risk and Exploitability
The CVSS base score of 5.4 indicates a moderate impact, while the EPSS score of less than 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no known public exploitation. Based on the description, it is inferred that exploitation can be performed without pre‑existing privileges. The likely attack vector is a client‑side XSS attack that delivers spoofed content when a user accesses a vulnerable page.
OpenCVE Enrichment