Impact
The vulnerability is a cross‑site scripting (XSS) flaw that allows an unauthenticated attacker to inject malicious input into web page generation, resulting in spoofing over the network. This can compromise user experience and potentially redirect or falsify content presented to users, thereby undermining the integrity of the service.
Affected Systems
Microsoft SharePoint Online is affected; no specific version details are provided beyond the product designation. The vulnerability impacts all deployments of the identified Microsoft SharePoint Online service that are reachable from the Internet.
Risk and Exploitability
The CVSS score of 9.6 signifies a high‑severity flaw. EPSS is reported as < 1%, indicating a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is client‑side input fed into SharePoint Online’s web page rendering. Exploitation requires no privileged access, relying only on the ability to submit malicious content to the vulnerable service.
OpenCVE Enrichment