Impact
Microsoft SharePoint Server systems are vulnerable to an external control of file name or path flaw that allows a user with authorized write access to craft file names or paths that are interpreted by the server as originating from another source. This weakness enables an attacker to display content to other users or administrators as if it were legitimate, potentially leading to the delivery of malicious content or the spread of misinformation. The flaw does not give the attacker the ability to execute arbitrary code but provides a means to subvert user trust, which can be leveraged in phishing or social engineering attacks within the network.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition are affected lines is present in the core file name/path handling code and no specific version ranges are identified in the advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an attacker to hold authorized credentials that allow file upload or linking, the attack surface is limited to authenticated users with such privileges. The attacker can exploit the lack of proper sanitization by uploading or referencing a file with a crafted name or path that displays as if it were from.
OpenCVE Enrichment