Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
GHSA-4vrf-42cm-7xfw | TastyIgniter vulnerable to Cross-Site Scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 20 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-434 CWE-79 |
|
Metrics |
cvssV3_1
|
Mon, 20 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-20T15:38:57.855Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61417

Updated: 2025-10-20T15:37:18.400Z

Status : Received
Published: 2025-10-20T15:15:33.700
Modified: 2025-10-20T16:15:39.510
Link: CVE-2025-61417

No data.

No data.