CVE-2025-47733

Published May 8, 2025

Last updated a month ago

Overview

Description
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
Source
secure@microsoft.com
NVD status
Analyzed
CNA Tags
exclusively-hosted-service

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-918

Social media

Hype score
Not currently trending
  1. ماکروسافت به تازگی برای ۴ آسیب پذیری که برای سرویس Azure cloud و Power Apps منتشر شده است ، پچ لازم را ارائه داده است. این آسیب پذیری ها دارای کدهای شناسایی CVE-2025-29813 و

    @AmirHossein_sec

    18 May 2025

    32 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️Actualizaciones mensuales de Microsoft ❗CVE-2025-29813 ❗CVE-2025-29972 ❗CVE-2025-29827 ❗CVE-2025-47733 ➡️Más info: https://t.co/bB03utcmcw https://t.co/uwmTwujltX

    @CERTpy

    16 May 2025

    116 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 A critical SSRF flaw in Microsoft Power Apps (CVE-2025-47733) puts internal data at risk. No auth needed. High CVSS: 9.1. Read how to protect your org now: https://t.co/8oJ6jJYcrl #CyberSecurity #SSRF #Microsoft #InfoSec

    @threatsbank

    10 May 2025

    40 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 🚨 CVE-2025-47733 ⚠️🔴 CRITICAL (9.1) 🏢 Microsoft - Microsoft Power Apps 🏗️ N/A 🔗 https://t.co/dDYUc5ufXp #CyberCron #VulnAlert #InfoSec https://t.co/WIY10BmTXs

    @cybercronai

    9 May 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2025-47733: CRITICAL] Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network#cve,CVE-2025-47733,#cybersecurity https://t.co/WHi7VQt3ed https://t.co/GTs9WtjkyR

    @CveFindCom

    9 May 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.