Impact
Improper neutralization of user‑supplied input during web page generation in Microsoft SharePoint Server enables a cross‑site scripting flaw that can be exploited for user spoofing. The vulnerability allows an attacker to inject script content into SharePoint pages, thereby presenting themselves as a legitimate user to other network users. This is a classic input validation weakness identified as CWE‑79 and could facilitate social‑engineering or malicious code execution when victims load the compromised content in their browsers.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are affected. No specific patch versions are listed beyond the product families, so administrators should review all instances of these SharePoint editions and apply appropriate updates whenever released.
Risk and Exploitability
The CVSS base score of 7.3 indicates high severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be user‑initiated, as an authorized attacker must have rights to create or modify pages—meaning the attacker must be authenticated and possess sufficient privileges to inject the malicious code. Based on the description, it is inferred that the exploit can be carried out over the network when a victim’s browser renders the compromised page.
OpenCVE Enrichment