Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2025-61417

11 месяцев назад

Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4vrf-42cm-7xfw

11 месяцев назад

TastyIgniter vulnerable to Cross-Site Scripting

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-61417

Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-4vrf-42cm-7xfw

TastyIgniter vulnerable to Cross-Site Scripting

1%
Низкий
11 месяцев назад

Уязвимостей на страницу