Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the sanitization procedure. No publicly available exploits are known
References
Configurations
No configuration.
History
31 Oct 2025, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-31 09:15
Updated : 2025-10-31 09:15
NVD link : CVE-2025-30191
Mitre link : CVE-2025-30191
CVE.ORG link : CVE-2025-30191
JSON object : View
Products Affected
No product.
CWE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
