PT-2025-32431 · Minio+1 · Minio+1

N1N3B9S

·

Published

2025-08-09

·

Updated

2025-08-11

·

CVE-2025-8750

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions macrozheng mall versions up to 1.0.3
Description A vulnerability exists in the Upload function of the /minio/upload file within the Add Product Page component. Manipulation of the File argument can lead to cross-site scripting (XSS). This issue is remotely exploitable. The exploit has been publicly disclosed. The vendor was notified but did not respond.
Recommendations Versions prior to 1.0.3: Address the vulnerability by sanitizing or validating the File argument within the Upload function of the /minio/upload file. As a temporary workaround, consider restricting file uploads to known safe types.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-8750

Affected Products

Minio
Macrozheng Mall