Impact
Microsoft SharePoint Server Subscription Edition suffers from improper neutralization of user input when generating web pages, leading to a cross‑site scripting vulnerability. An authorized attacker can inject malicious scripts that are served to end users, allowing the attacker to impersonate legitimate content or user identities, carry out phishing attacks, or steal credentials. This flaw compromises the integrity and authenticity of the web interface.
Affected Systems
Affected systems are Microsoft SharePoint Server Subscription Edition installations. No specific version list is provided by the CNA, so any deployed instance that allows content generation without proper input filtering is potentially vulnerable.
Risk and Exploitability
The CVSS score is 4.6, indicating a moderate severity flaw. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation at this time. The likely attack vector is an authenticated user or application with authorized permissions who can create or edit content on SharePoint; the flaw is triggered when the injected script is rendered to viewers, causing client‑side execution. The risk is primarily to authentication and trust, with potential for credential theft or malicious navigation.
OpenCVE Enrichment