Impact
This vulnerability involves improper neutralization of user input during web page generation in Microsoft SharePoint, leading to a cross‑site scripting problem. An attacker who already has authorized access can inject malicious content that is rendered as part of a SharePoint page, allowing the attacker to spoof legitimate users or branding in the network environment. The weakness is a typical input validation flaw listed as CWE‑79, and the primary impact is the potential to deceive users or administrators by tricking them into believing that content originates from a trusted source.
Affected Systems
Affected are Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition. No explicit sub‑version or patch level is listed, so all installations of these products should be examined for the presence of this issue.
Risk and Exploitability
The CVSS score is 4.6, indicating a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation or high likelihood of being targeted. Likely attack vectors require an attacker to be authenticated as an authorized user or to have some form of privileged access to the SharePoint server. Once authenticated, the attacker can supply crafted input that is inadequately sanitized, resulting in page spoofing. Because the flaw resides in content generation and there are no public exploitation reports, the overall risk remains moderate but should not be ignored.
OpenCVE Enrichment