Impact
Improper neutralization of input is found in Microsoft SharePoint during the generation of web pages, qualifying as a cross‑site scripting flaw. The primary impact is that an attacker who is authenticated can inject malicious code that is rendered as part of a SharePoint page, enabling the attacker to present fabricated or misleading content to other users. This type of weakness is a classic XSS (CWE‑79) that can lead to spoofing of legitimate SharePoint information.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, while the EPSS score of < 1 % denotes a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker needs valid credentials and the ability to modify page content in order to execute the exploit. Successful exploitation would allow the attacker to spoof content presented to other authenticated users across the SharePoint network.
OpenCVE Enrichment