Логотип exploitDog
bind:CVE-2025-51489
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-51489

Количество 2

Количество 2

nvd логотип

CVE-2025-51489

6 месяцев назад

A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upload a malicious SVG file when creating/updating an Article and correctly execute arbitrary JavaScript when the file link is opened.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-8xfq-7f6m-mpmf

6 месяцев назад

MoonShine Arbitrary File Upload Vulnerability

CVSS3: 4.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-51489

A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upload a malicious SVG file when creating/updating an Article and correctly execute arbitrary JavaScript when the file link is opened.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-8xfq-7f6m-mpmf

MoonShine Arbitrary File Upload Vulnerability

CVSS3: 4.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу