Impact
Improper neutralization of input during web page generation in Microsoft SharePoint leads to a classic cross‑site scripting weakness. An attacker who already has authorised access can inject malicious content into a page that is rendered as if it originated from another trusted source, enabling the attacker to spoof information or trick users into interacting with a falsified interface. The CW 79 weakness allows the attacker to influence the HTML that other users receive, potentially compromising the user’s trust in the site and enabling phishing or credential theft.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are all susceptible to this flaw as documented by Microsoft’s advisory.
Risk and Exploitability
The CVSS score of 4.6 describes a medium‑severity risk. No EPSS score is currently publicly available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access to the SharePoint environment, an attacker must already possess valid credentials or be a recognised user. Exploitation therefore is not guaranteed to be convenient for unauthenticated threat actors, but the ability to impersonate or alter web page content can still enable significant social‑engineering attacks within the organisation.
OpenCVE Enrichment