Impact
The vulnerability is improper neutralization of user‑supplied input during web page generation in Microsoft SharePoint Server Subscription Edition, which allows an authorized attacker to inject malicious scripts into rendered pages. This cross‑site scripting flaw (CWE‑79) can be used for spoofing, enabling the attacker to present content that appears to come from trusted sources to other users interacting with the affected SharePoint environment.
Affected Systems
Affected systems include Microsoft SharePoint Server Subscription Edition. No specific version numbers are listed in the CNA data, so all deployments of this edition may be impacted until an update is applied.
Risk and Exploitability
The CVSS score of 3.5 indicates moderate severity, and the EPSS score is not available, suggesting low publicly documented exploitation activity. Because the flaw requires previously authenticated access, an attacker must be authorized to create or edit pages. If such access exists, the attacker could inject scripts that could trick users into interacting with forged UI. The vulnerability is not listed in CISA KEV, and no public exploit has been documented, but organizations should still consider precautionary measures.
OpenCVE Enrichment