Medium severity6.5NVD Advisory· Published Jun 16, 2025· Updated Apr 15, 2026
CVE-2025-25264
CVE-2025-25264
Description
An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.