Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A cross-site scripting vulnerability has been identified in Microsoft Edge (Chromium-based) version 150.0.4078.48. This issue arises from improper input neutralization during web page generation, allowing an unauthorized attacker to perform spoofing over the network. Exploitation could enable the attacker to host a specially crafted website that, when viewed by a user, could read information from the user's browser related to the vulnerable URL and send it to the attacker.
Successful exploitation could lead to spoofing attacks, with the potential for an attacker to read and manipulate information in the victim's browser associated with the vulnerable URL.
Users can download the security update for Microsoft Edge (Chromium-based) version 150.0.4078.48 through the Microsoft Edge Update mechanism or by downloading the update from the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.