Impact
The vulnerability originates from improper neutralization of user supplied input during the generation of web pages in Skype for Business. This cross‑site scripting flaw permits an attacker to inject malicious content that causes end‑users to believe they are interacting with a legitimate participant, leading to spoofing over the network.
Affected Systems
The flaw affects Microsoft Skype for Business Server 2015 Community Update 13, Microsoft Skype for Business Server 2019 Update 8, and Microsoft Skype for Business Server Subscription Edition Update 1. Only the specified cumulative update levels are known to be vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity that could be leveraged by an attacker who can supply input that is rendered in a web context. No exploitable code or remote code execution is required; spoofing attacks rely on user interaction with a crafted web page. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, meaning it has not yet been confirmed as a known exploited vulnerability. Nevertheless, the potential for social engineering and the impact on user trust warrants timely remediation.
OpenCVE Enrichment