Server-Side Request Forgery in Microsoft Power Apps
CVE-2025-47733

9.1CRITICAL

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
8 May 2025

Summary

A vulnerability in Microsoft Power Apps allows an attacker to exploit Server-Side Request Forgery (SSRF) to gain unauthorized access to sensitive information over a network. This could potentially lead to data leaks and compromise user privacy. Users of Power Apps should remain vigilant and apply security updates to mitigate the risk associated with this vulnerability. For detailed information, you can refer to the Microsoft advisory linked.

Affected Version(s)

Microsoft Power Apps Unknown

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47733 : Server-Side Request Forgery in Microsoft Power Apps | SecurityVulnerability.io