Impact
Improper neutralization of special elements in an SQL command allows attackers to inject malicious statements into a database query. The weakness is a classic SQL injection flaw, identified as CWE-89. When exploited, it can expose sensitive data stored in the SharePoint database to an attacker through network traffic, compromising confidentiality.
Affected Systems
Microsoft SharePoint Server Subscription Edition is affected. No specific affected version numbers are listed in the available data.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the medium to high range, indicating that an attacker could gain significant access to confidential information. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation is publicly known yet. The likely attack vector is an authorized user who can submit queries to SharePoint; therefore it requires legitimate credentials but not necessarily remote access to the application itself.
OpenCVE Enrichment