Impact
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to spoof information over a network. The flaw can lead to deceptive data presentation or duplicate content, undermining user confidence and possibly giving the attacker the appearance of legitimate content delivery. The weakness is identified as CWE‑20 – Improper Input Validation.
Affected Systems
The vulnerability affects Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. These products are covered by the Microsoft CNA and are impacted until a suitable patch is deployed.
Risk and Exploitability
The CVSS score of 4.6 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires an authenticated attacker who can submit crafted content to the affected SharePoint instance. The lack of a publicly disclosed exploit suggests the risk remains low, but the moderate base score underscores that the spoofing could result in significant confusion, data integrity issues, or unauthorized content rendering for users who rely on the affected SharePoint deployment.
OpenCVE Enrichment