Server-Side Request Forgery in Microsoft Power Apps
CVE-2025-47733
9.1CRITICAL
Summary
A vulnerability in Microsoft Power Apps allows an attacker to exploit Server-Side Request Forgery (SSRF) to gain unauthorized access to sensitive information over a network. This could potentially lead to data leaks and compromise user privacy. Users of Power Apps should remain vigilant and apply security updates to mitigate the risk associated with this vulnerability. For detailed information, you can refer to the Microsoft advisory linked.
Affected Version(s)
Microsoft Power Apps Unknown
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved