Impact
An attacker can inject unsanitized input into SharePoint pages, creating a cross‑site scripting flaw that enables website spoofing over the network. The attacker could alter page content or mimic legitimate users, leading to defacement, phishing, or other malicious impersonation activity. This vulnerability is categorized as a cross‑site scripting flaw.
Affected Systems
The affected products are Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition. Version details are not specified in the data, but any installation of the mentioned SharePoint editions could be impacted.
Risk and Exploitability
The CVSS score is 9.3, indicating high severity; the EPSS score is less than 1%, so exploitation is considered unlikely but still possible. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is over a network, where an unauthenticated or minimally privileged user could supply malicious input to a SharePoint page. The exploitation requires only the ability to deliver crafted input to the vulnerable SharePoint instance.
OpenCVE Enrichment