Impact
The vulnerability arises from improper neutralization of user input during generation of web pages in Microsoft SharePoint, a classic cross‑site scripting flaw (CWE‑79). An attacker who is already authorized on the SharePoint instance can inject crafted scripts or HTML that will be rendered on the page for other users, enabling them to perform spoofing such as displaying messages that appear to come from the system or other users and potentially deceiving administrators or end‑users.
Affected Systems
Microsoft identifies the affected products as SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. The vendor did not provide a sub‑version list; any installation of these releases is considered vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the attack vector would generally require the attacker to hold authenticated access to the SharePoint environment; exploiting it may involve creating or modifying content in a site that other users will view. The CVSS score of 7.3 reflects a high impact and moderate to high exploitability. However, the EPSS score is below 1%, indicating a very low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment