CVE-2025-30191
MEDIUMEmail - CSRF
Title source: llmDescription
Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the sanitization procedure. No publicly available exploits are known
Scores
CVSS v3
5.4
EPSS
0.0005
EPSS Percentile
14.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Classification
CWE
CWE-1021
Status
draft
Timeline
Published
Oct 31, 2025
Tracked Since
Feb 18, 2026