Impact
Improper neutralization of user input during web page generation on Microsoft SharePoint leads to a cross‑site scripting flaw that can allow an attacker to inject malicious scripts into pages. The injected code can mimic legitimate site behavior, causing users to be misled or to unknowingly submit sensitive information to the attacker. This classic XSS weakness (CWE‑79) primarily threatens the integrity of page content and the trust users place in the site, potentially enabling social‑engineering attacks rather than direct code execution.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are all affected by this flaw. No specific build or patch level is listed, so all current installations of these products are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 4.6 classifies the issue as medium severity. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through web content that an authorized user can edit; based on the description, it is inferred that the attacker must first have edit or add‑content permissions to insert malicious scripts, after which other users viewing the crafted page will execute the injected code.
OpenCVE Enrichment