PT-2025-23283 · Unknown · Asset Suite

Published

2025-05-30

·

Updated

2025-07-15

·

CVE-2025-1484

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Asset Suite versions (affected versions not specified)
Description A vulnerability exists in the media upload component. If successfully exploited, an attacker could impact the confidentiality or integrity of the system. An attacker can use this vulnerability to construct a request that will cause JavaScript code supplied by the attacker to execute within the user’s browser in the context of that user’s session with the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2025-1484

Affected Products

Asset Suite