CVE-2025-25001
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 79
Summary
CVE-2025-25001 is a cross-site scripting (XSS) vulnerability affecting Microsoft Edge, the Chromium-based web browser. This issue arises from Microsoft Edge's failure to adequately neutralize user input during web page generation. An attacker, who is not authorized, can exploit this vulnerability to execute malicious scripts in a user's web browser, potentially leading to spoofing attacks over a network. These attacks can trick users into divulging sensitive information or taking unwanted actions, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Edge
Affected Vendors
- Microsoft