PT-2025-34597 · Joomla+1 · Joomla!+1

Sebastian Jeż

·

Publicado

2025-08-25

·

Atualizado

2025-08-25

·

CVE-2025-54300

CVSS v4.0

8.5

Alta

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: Quantum Manager versions 1.0.0 through 3.2.0
Description: A stored cross-site scripting (XSS) issue was identified in the Quantum Manager component for Joomla. The SVG upload feature does not properly sanitize uploaded files, allowing for the injection of persistent scripts.
Recommendations: Quantum Manager version 3.2.0 and earlier: Ensure all SVG uploads are properly sanitized to prevent the injection of malicious code.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-54300

Produtos afetados

Joomla!
Quantum Manager