PT-2025-42769 · Unknown · Tastyigniter
Publicado
2025-10-20
·
Atualizado
2025-10-21
·
CVE-2025-61417
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TastyIgniter version 3.7.7
Description
A Cross-Site Scripting (XSS) issue exists in the /admin/media manager component. An attacker can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser, potentially allowing the attacker to perform unauthorized actions, such as modifying admin account credentials. The vulnerable component is the
/admin/media manager endpoint, and the attack involves uploading a malicious SVG file. The SVG file contains JavaScript code that executes when previewed. The administrator account is at risk of compromise.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, avoid previewing SVG files uploaded through the
/admin/media manager component.Exploit
Correção
XSS
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tastyigniter