Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
2025-07-08T17:15:57.867
2025-10-27T17:12:33.713
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | microsoft | sharepoint_server | 2016 | Yes |
| Application | microsoft | sharepoint_server | 2019 | Yes |