Skip to main content

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Severity

CVSS 3.1 · CNA4.6 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C
SSVC · CISA-ADP
Exploitationnone
Automatableno
Technical impactpartial

Affected Products

VendorProductAffected versions
MicrosoftMicrosoft SharePoint Enterprise Server 2016
16.0.0 to <16.0.5548.1003
MicrosoftMicrosoft SharePoint Server 2019
16.0.0 to <16.0.10417.20114
MicrosoftMicrosoft SharePoint Server Subscription Edition
16.0.0 to <16.0.19725.20210

References

1 Links

Record Details

Published
2026-04-14
Last updated
2026-09-25
Assigner (CNA)
microsoft
Credited to
-

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.