Impact
This vulnerability arises from improper neutralization of user input during web page generation in Microsoft Office SharePoint. The flaw permits an attacker who has authorized access to the SharePoint environment to inject malicious content that can deceive users, effectively enabling spoofing attacks. Because the injected script runs in the victim's browser context, the attacker can modify the appearance or behavior of pages without their knowledge, thereby compromising the integrity of the information displayed.
Affected Systems
The issue affects Microsoft SharePoint Server Subscription Edition. No specific version range was provided in the CNA data, so any deployment of this product edition that has not installed the latest security update may be vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates a high risk severity. The exploit requires the attacker to have authorized access or privileges sufficient to add or edit web pages. Once those conditions are met, the attacker can craft malicious input that is not properly sanitized. Because the exploitation vector is internal or requires authenticated user rights, the likelihood remains limited to users with sufficient permissions, and it is not listed in CISA's KEV catalog. However, the high score and the potential for deceptive attacks underscore the need for timely remediation.
OpenCVE Enrichment