Impact
The vulnerability is an improper neutralization of input during web page generation, a cross‑site scripting flaw that allows an attacker with authorized access to inject malicious content into SharePoint pages. By exploiting this flaw, the attacker can make a legitimate page appear to originate from a trusted source, potentially misleading site visitors and compromising internal authenticity. The primary consequence is user interface spoofing, which can erode trust and enable further social‑engineering attacks.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. No specific sub‑version information is listed.
Risk and Exploitability
The CVSS score of 4.6 indicates a moderate severity. The EPSS score of less than 1% shows a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker must already have authorized access to the SharePoint instance; using that privilege, they can remotely execute the XSS payload over the network to achieve spoofing.
OpenCVE Enrichment