Skip to content
Auto-CTI
Back to today
NEW MEDIUM A3

Microsoft Edge: Vulnerability allows Cross-Site Scripting

A BSI Warn- und Informationsdienst (WID): Schwachstellen-Informationen (Security Advisories) ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

The vulnerability affects Microsoft Edge, which is used in the company, and allows XSS and spoofing attacks.

Description

Microsoft Edge contains a vulnerability that allows a remote, anonymous attacker to conduct a spoofing and cross-site scripting attack. No CVE number has been assigned to the vulnerability yet. It is not known whether the vulnerability is being actively exploited. The vulnerability affects the Microsoft Edge browser.

Risk score

0
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC