Impact
The flaw is an improper neutralization of user input during web page generation, resulting in a cross‑site scripting (XSS) vulnerability. An attacker who can supply specially crafted input to the Azure Portal is able to inject malicious content that is rendered to other users. This enables spoofing, allowing the attacker to convince legitimate users that they are interacting with legitimate portal pages while actually seeing attacker‑controlled content. The injected content can mimic authentic portal elements, potentially leading to phishing or credential theft.
Affected Systems
Microsoft Azure Portal is the affected product. Specific version information is not disclosed, so all Azure Portal instances remain potentially impacted until a vendor‑provided patch is applied.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, yet the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying it has not been actively exploited in the wild. Likely access requires the attacker to influence input that the portal processes—this could be achieved through network access to the portal's interface or by tricking a user into submitting malicious data. Because the flaw does not require privileged access, any user with the ability to interact with the portal could potentially be exploited.
OpenCVE Enrichment