Cross-Site Scripting Vulnerability in Microsoft Edge by Microsoft
CVE-2025-25001

4.3MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
4 April 2025

Summary

A vulnerability exists due to improper input neutralization during web page generation in Microsoft Edge. This flaw enables unauthorized attackers to execute spoofing attacks over a network, potentially compromising user security and trust. Users of Microsoft Edge are recommended to stay updated with the latest patches to mitigate risks associated with this issue.

Affected Version(s)

Microsoft Edge for iOS Unknown 1.0.0.0 < 132.0.2957.118

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.