Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-31011 | Mangati NovoSGA XSS vulnerability in /admin |
![]() |
GHSA-4c44-r8rm-3p39 | Mangati NovoSGA XSS vulnerability in /admin |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 15 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 13 Oct 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. |
Metrics |
cvssV2_0
|
cvssV2_0
|
Thu, 25 Sep 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mangati
Mangati novosga |
|
Vendors & Products |
Mangati
Mangati novosga |
Wed, 24 Sep 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Mangati NovoSGA SVG File admin cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-10-15T16:02:23.525Z
Reserved: 2025-09-24T10:21:41.685Z
Link: CVE-2025-10909

Updated: 2025-09-24T17:51:23.211Z

Status : Awaiting Analysis
Published: 2025-09-24T17:15:40.123
Modified: 2025-10-15T16:15:33.733
Link: CVE-2025-10909

No data.

Updated: 2025-09-25T08:21:19Z