PT-2025-42769 · Unknown · Tastyigniter
Published
2025-10-20
·
Updated
2025-10-21
·
CVE-2025-61417
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TastyIgniter version 3.7.7
Description
A Cross-Site Scripting (XSS) issue exists in the /admin/media manager component. An attacker can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser, potentially allowing the attacker to perform unauthorized actions, such as modifying admin account credentials. The vulnerable component is the
/admin/media manager endpoint, and the attack involves uploading a malicious SVG file. The SVG file contains JavaScript code that executes when previewed. The administrator account is at risk of compromise.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, avoid previewing SVG files uploaded through the
/admin/media manager component.Exploit
Fix
XSS
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tastyigniter