Impact
This vulnerability arises from the failure to neutralize user‑supplied data when generating web pages in Microsoft SharePoint. An attacker with authorized access can embed malicious scripts that trick users into believing the content originates from a legitimate source, effectively creating a spoofing environment that can be used for phishing or defacement.
Affected Systems
Microsoft SharePoint Server Subscription Edition is affected. No specific version numbers are listed in the CNA data, so all deployed instances of this product edition are considered vulnerable until the issued patch is applied.
Risk and Exploitability
With a CVSS score of 7.3 the issue is considered high severity. The EPSS score is not available, and the vulnerability is not included in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector requires an attacker that already has authorized privileges within the SharePoint environment; a compromised or privileged user could inject the malicious payload into a page.
OpenCVE Enrichment