Impact
This vulnerability is an instance of improper neutralization of user supplied input during SharePoint web page rendering. An attacker who already has legitimate credentials can insert a malicious payload into content that is later served to other users. When that content is displayed, the browser executes the script, enabling the attacker to modify the visual appearance of pages or embed deceptive elements. The impact is a spoofing attack that can mislead users into believing they are interacting with authentic SharePoint content, without granting any new privileges or bypassing authentication.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. The issue applies to all released versions of these products where user‑controlled content is rendered without proper encoding.
Risk and Exploitability
The CVSS score of 4.6 classifies the vulnerability as moderate. The EPSS score of less than 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have valid credentials to add or edit content and to be able to inject a crafted script. Once those conditions are met, the script runs in the victim’s browser, enabling spoofing but not compromising overall system integrity or confidentiality.
OpenCVE Enrichment