Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A server-side request forgery (SSRF) vulnerability has been identified in Microsoft Edge (Chromium-based) version 150.0.4078.48. This vulnerability allows an unauthorized attacker to perform spoofing over a network. The issue arises from the way the browser handles certain requests, potentially allowing attackers to manipulate server interactions.
Exploitation of this vulnerability could lead to unauthorized network spoofing, allowing attackers to impersonate other entities or services.
To exploit this vulnerability, an attacker could host a specially crafted website designed to take advantage of the SSRF flaw in Microsoft Edge. The attacker would need to convince a user to visit the website, such as through an email or message enticement, or by sending an attachment that prompts the user to open it.
Users can download the security update for Microsoft Edge (Chromium-based) version 150.0.4078.48 from the Microsoft Edge Security Update page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.