Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A server-side request forgery (SSRF) vulnerability has been identified in Microsoft Edge (Chromium-based) version 150.0.4078.48. This vulnerability allows an unauthorized attacker to perform network spoofing. Exploitation could lead to the attacker reading information from the victim's browser related to the vulnerable URL, potentially allowing for spoofing attacks over the network.
Exploitation of this vulnerability could result in spoofing attacks, with an important severity level.
To reproduce this vulnerability, an attacker could host a specially crafted website designed to exploit the SSRF vulnerability in Microsoft Edge. The attacker would need to convince a user to visit the website, such as through an email or message enticement, or by sending an attachment that prompts the user to open it.
Users can download the security update for this vulnerability through the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.