Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-25264


An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.


Published

2025-06-16T10:15:19.517

Last Modified

2025-11-21T12:15:46.477

Status

Awaiting Analysis

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-942

Affected Vendors & Products

-


References