← Back

CVE-2025-61417

nvd nist
Published: Oct 20, 2025Modified: Nov 12, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.

Affected (1)

1 product
Tastyigniter
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.7.7

References (2)

Source: cve@mitre.org
ExploitThird Party Advisory

Timeline

No history available yet.