Impact
The vulnerability is a server‑side request forgery (SSRF) that enables an unauthenticated attacker to provoke the SharePoint Online service to send requests to arbitrary internal or external targets, thereby performing network spoofing. The SSRF flaw can expose sensitive internal resources, facilitate lateral movement, or allow the attacker to exfiltrate data or request privileged information that the service would normally restrict.
Affected Systems
Microsoft SharePoint Online is affected; no specific version details are provided beyond the product designation. The vulnerability impacts all deployments of the identified Microsoft SharePoint Online service that are reachable from the Internet.
Risk and Exploitability
The CVSS score of 9.6 signifies a high‑severity flaw. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the public SharePoint Online endpoints; an attacker can inject a crafted URL to cause the service to request internal resources. The exploitation requires no privileged access, relying only on the ability to send an HTTP request to the vulnerable service.
OpenCVE Enrichment