Impact
An improper neutralization of input during web page generation creates a cross‑site scripting (CWE‑79) vulnerability that allows an authorized attacker to inject malicious content. By manipulating the rendered page, the attacker can spoof the identity of legitimate users or services, potentially leading to deception, unauthorized disclosure, or facilitation of further attacks within the network.
Affected Systems
Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server Subscription Edition RTM are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 7.3 indicates a moderate‑to‑high severity, while the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with sufficient privileges to generate web pages; the attacker would then inject XSS payloads that manipulate page content to perform spoofing across the network.
OpenCVE Enrichment