cbcvebase.
CVE-2025-47172
published 2025-06-10

CVE-2025-47172: Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected

9 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5504.100116.0.5504.1001
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10417.2001816.0.10417.20018
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.18526.2039616.0.18526.20396
microsoftsharepoint_enterprise_server
microsoftsharepoint_server<= 16.0.18526.20396
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_server_2019
msrcmicrosoft_sharepoint_server_subscription_edition