PT-2025-47537 · Icret · Easy Images

Naixiao

·

Published

2025-11-19

·

Updated

2025-11-20

·

CVE-2025-13415

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions icret EasyImages versions up to 2.8.6
Description A flaw exists in icret EasyImages, specifically within the SVG Image Handler component, affecting the file /app/upload.php. Manipulation of the File argument can lead to cross site scripting. This issue is potentially exploitable remotely.
Recommendations Update to a version later than 2.8.6.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13415

Affected Products

Easy Images