Impact
The vulnerability is an instance of improper input neutralization during web page generation, classified as a cross‑site scripting flaw (CWE‑79). A user who is already authorized to use the SharePoint server can inject malicious content that is later rendered by the web interface. The injected payload can appear as legitimate content to other users, effectively allowing the attacker to spoof the appearance or identity of the site or its components over the network.
Affected Systems
Affected installations include Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. These are the SharePoint Server products listed by the CNA, with no specific version ranges provided in the data; any installation of the listed products may be vulnerable if the corresponding security update has not been applied.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. The flaw requires that the attacker already have legitimate access to the SharePoint environment; from that position, the attacker can inject XSS code that other users will interpret, enabling spoofing of site content or user interfaces. The limited attack surface and low exploitation likelihood reduce the overall risk, but the ability to masquerade as legitimate content remains a concern for environments where insider threats are a possibility.
OpenCVE Enrichment