Microsoft SharePoint Server
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:*:*:*
A cross-site scripting vulnerability has been identified in Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. This vulnerability allows an unauthorized attacker to perform spoofing over a network by improperly neutralizing input during web page generation. Exploitation could enable the attacker to execute scripts in the context of the affected user.
Exploitation of this vulnerability could lead to unauthorized spoofing attacks over the network, allowing attackers to manipulate how users perceive or interact with the SharePoint application.
Users can download the security update for their specific SharePoint version from the Microsoft Update Catalog. Instructions for applying the update are available in the corresponding Knowledge Base articles.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.