Impact
The vulnerability in Microsoft Office SharePoint arises from improper neutralization of user input when generating web a classic cross‑site scripting (XSS) weakness that lets an attacker craft malicious content that the server will render. Because the vulnerability only affects users who already have authorized access, the attacker can alter the appearance of SharePoint pages, potentially creating a spoofed interface or misleading users. The primary impact is the ability to impersonate legitimate content or branding, which can undermine trust and facilitate social‑engineering attacks within the organization.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are affected. No specific revision numbers are supplied in the data, so any installed instance of these product lines is assumed to be vulnerable unless confirmed otherwise.
Risk and Exploitability
The CVSS score of 7.3 indicates a medium‑to‑high severity flaw. The EPSS score is reported as less than 1%, suggesting that exploitation is unlikely but still possible, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires the attacker to already have authorized access, the attack vector is internal and likely limited to users or processes within the same network or domain. Exploiting the XSS condition would involve supplying crafted input that the server fails to sanitize, leading to spoofed content being displayed to other authenticated users.
OpenCVE Enrichment