Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-45055

Опубликовано: 09 июн. 2025
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:silverpeas:silverpeas:6.4.2:*:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.00026
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
8 месяцев назад

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.

EPSS

Процентиль: 7%
0.00026
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79