Impact
A server‑side request forgery vulnerability in Microsoft Office SharePoint enables an attacker who already has legitimate access to the SharePoint environment to make the SharePoint server issue HTTP requests to arbitrary internal or external addresses. By reading the responses from these requests, the attacker can obtain data that would otherwise be inaccessible, leading to accidental or intentional exposure of confidential information.
Affected Systems
Microsoft SharePoint Server Subscription Edition is the impacted product. The CVE description does not specify which releases are affected, and no version information is provided in the CNA data, so the scope of the vulnerability across releases remains uncertain.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of current exploitation. The attack requires the attacker to be authorized to use the SharePoint system, limiting exposure to organizations that depend on SharePoint for sensitive operations. The ability to read arbitrary network resources could compromise confidentiality and potentially serve as a foothold for lateral movement if additional privileges exist.
OpenCVE Enrichment