Impact
Server‑side request forgery (SSRF) in Microsoft SharePoint Server allows an authorized attacker to cause the server to issue HTTP requests to arbitrary addresses over a network, effectively spoofing outbound traffic. This vulnerability is identified as CWE‑918.
Affected Systems
The vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific minor patch levels are listed, but the flaw exists in all listed product versions.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact level. The EPSS score of less than 1% suggests that exploitation attempts are rare. The vulnerability is not listed in the CISA KEV catalog. Because it requires authorized access to a SharePoint site, the attacker must first be authenticated before the SSRF can be leveraged to cause the server to send forged requests.
OpenCVE Enrichment