Impact
Improper neutralization of input during web page generation exposes a cross‑site scripting flaw that an authorized attacker can exploit to spoof content seen by other users on the network. The flaw does not allow arbitrary code execution but enables the attacker to impersonate legitimate users or alter displayed information, potentially misleading users and compromising the appearance of authenticity within SharePoint sites.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are vulnerable. No specific build numbers are listed; all standard releases of these products are affected.
Risk and Exploitability
The CVSS score of 4.6 indicates a moderate impact with a low exploitation probability reflected by an EPSS of less than 1 %. The vulnerability is not listed in CISA’s KEV catalog. Because the attacker must already have authorized access, the attack vector is limited to individuals with legitimate SharePoint credentials, but compromised credentials or social engineering could enable broader exposure over the network.
OpenCVE Enrichment