Microsoft SharePoint Server Subscription Edition
cpe:2.3:a:microsoft:sharepoint_enterprise_server:*:*:*:*:*:*:*
A cross-site scripting vulnerability has been identified in Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. This vulnerability allows an authorized attacker to perform spoofing over the network by improperly neutralizing input during web page generation.
Exploitation of this vulnerability could lead to spoofing attacks, allowing an attacker to impersonate another user or entity.
Users can download the security update for Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 from the Microsoft Update Catalog. Instructions for downloading the security update are available on the Microsoft Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.