Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tastyigniter
Tastyigniter tastyigniter |
|
| Vendors & Products |
Tastyigniter
Tastyigniter tastyigniter |
Mon, 20 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 CWE-79 |
|
| Metrics |
cvssV3_1
|
Mon, 20 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-10-20T00:00:00.000Z
Updated: 2025-10-20T15:38:57.855Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61417
Updated: 2025-10-20T15:37:18.400Z
Status : Awaiting Analysis
Published: 2025-10-20T15:15:33.700
Modified: 2025-10-21T19:31:25.450
Link: CVE-2025-61417
No data.