Impact
The flaw is an improper neutralization of user input during the rendering of SharePoint pages, enabling a cross‑site scripting attack. An attacker who already has authorized access can embed malicious scripts into SharePoint content; when a target user views the page, the script runs with the privileges of that user, allowing the attacker to elevate privileges, manipulate data, or move laterally within the network.
Affected Systems
Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition are affected. The vulnerability applies to all versions of these products unless an update has been applied. Exact version ranges are not supplied in the CNA data.
Risk and Exploitability
The high severity CVSS score of 7.3 indicates significant risk, yet the EPSS score of less than 1% shows that exploitation is currently unlikely. Because the flaw requires authenticated access, it is not listed in the CISA KEV catalog. The attack vector is inferred to be authenticated web requests that inject script content into SharePoint pages, which is later rendered in the target browser.
OpenCVE Enrichment