Impact
The vulnerability is a cross‑site scripting flaw that arises from inadequate neutralization of user input during web page generation in Microsoft SharePoint. An attacker who already has authorized access can inject malicious scripts into a page, resulting in spoofing attacks that allow the attacker to impersonate legitimate users or alter page appearance. The primary impact is the potential for social engineering or misinformation within the SharePoint environment.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are vulnerable. The issue affects the SharePoint web parts that render user‑supplied content on the server side. The affected product family includes SharePoint Server 2016, SharePoint Server 2019, and the subscription‑based edition.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation is known. The attack requires that the adversary be an authenticated user with permissions to add or edit page content, which limits the threat to insider or compromised accounts. The attacker must be authorized, inferred from the description, and this access requirement reduces the overall risk, although the potential impact on content integrity remains significant.
OpenCVE Enrichment