PT-2025-4852 · Unknown · Tandoor Recipes

M10X

·

Published

2025-01-28

·

Updated

2025-01-28

·

CVE-2025-23213

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tandoor Recipes versions prior to 1.5.28
Description The issue concerns the file upload feature in Tandoor Recipes, which allows uploading arbitrary files, including html and svg. These files can contain malicious content, such as XSS payloads.
Recommendations For versions prior to 1.5.28, update to version 1.5.28 to resolve the issue. As a temporary workaround, consider restricting the file upload feature to minimize the risk of exploitation. Avoid using the file upload feature for html and svg files until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-23213
GHSA-56JP-J3X5-HH2W

Affected Products

Tandoor Recipes