PT-2025-52373 · Microsoft · Azure Cosmos Db

Jianyang Song

·

Published

2025-12-18

·

Updated

2025-12-24

·

CVE-2025-64675

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Azure Cosmos DB (affected versions not specified)
Description An issue exists in Azure Cosmos DB related to improper neutralization of input during web page generation, leading to a cross-site scripting condition. This allows an unauthorized attacker to perform spoofing over a network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-64675

Affected Products

Azure Cosmos Db