Impact
An attacker who is not authorized can inject malicious scripts into web pages generated by Skype for Business Server. The cross‑site scripting flaw allows the injected code to run in the context of the victim's session, enabling the attacker to make the system appear to be communicating with a different user or service, thereby spoofing identities over the network.
Affected Systems
The vulnerability affects Microsoft Skype for Business Server 2015 on CU13, Skype for Business Server 2019 on CU8, and Skype for Business Server Subscription Edition on CU1. All three product lines suffer from the same cross‑site scripting flaw that can be exploited by any user who can load a manipulated web page.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting the threat is not widely exploited yet. The likely attack vector is a web‑based one, with an attacker sending malicious content to a user who then interacts with a compromised web page. The impact is the ability to impersonate another user or service within Skype for Business, potentially leading to misinformation or deception of other participants.
OpenCVE Enrichment