Impact
The flaw is an improper neutralization of input in the SharePoint web page generation process, which is a classic cross‑site scripting (CWE‑79) vulnerability. An attacker who is already authenticated to the SharePoint instance can inject malicious scripts that are rendered in users’ browsers, enabling the attacker to forge messages or content and convince other users that the data originates from a trusted source. This can compromise the integrity of shared resources and lead to user confusion or data tampering. The impact is limited to the scope of the authenticated attacker’s permissions; it does not provide arbitrary code execution on the server.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. The vulnerability exists in the web page rendering component of these products, regardless of the operating system underlying the SharePoint deployment.
Risk and Exploitability
The CVSS score of 4.6 reflects a moderate impact, and the EPSS score is below 1 %, indicating a very low historical exploitation probability. The vulnerability is not currently listed in the CISA KEV catalog. Because the flaw requires an authenticated user with write or edit permissions, the attack vector is internal or through a compromised account; remote unauthenticated exploitation is not possible.
OpenCVE Enrichment