Impact
Microsoft Office SharePoint is vulnerable to an improper neutralization of input during web page generation, a classic cross‑site scripting flaw. The flaw permits an authorized attacker to inject malicious content that is rendered as legitimate SharePoint pages, enabling spoofing of legitimate users and systems over the network. The impact is primarily deceptive, allowing the attacker to impersonate a trusted source, potentially leading to phishing, credential theft, or further lateral movement when users interact with the spoofed content.
Affected Systems
The vulnerability affects Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition. Only these product lines are listed as impacted; no specific version numbers are provided beyond the product family.
Risk and Exploitability
The CVSS score of 8 indicates a high severity level, and the EPSS score of 0.0049 (less than 1%) indicates a very low, but non‑zero, exploitation probability. The vulnerability is not listed in the CISA KEV catalog, so a known exploit has not been documented yet. The attack requires the attacker to already possess authorized access to a SharePoint instance. Once that condition is met, the XSS flaw can be leveraged to serve crafted pages that masquerade as legitimate content, potentially tricking users into divulging credentials or executing other malicious actions.
OpenCVE Enrichment