Impact
Improper neutralization of cross‑site scripting in Microsoft SharePoint Server allows an attacker who can edit site content to inject malicious code that is rendered by the server. This flaw can lead to spoofing of web pages or user interfaces, causing users to see deceptive content.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. No specific patch version ranges are listed in the CNA details, so all installations of the mentioned editions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is internal with authenticated access; an authorized content editor can submit malicious input that is rendered without proper escaping, resulting in spoofing of an intranet page. The impact is confined to the SharePoint environment, and users accessing compromised pages may be deceived.
OpenCVE Enrichment