CVE-2025-61417
Last modified
CVE-2025-61417 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tastyigniter | Tastyigniter | 3.7.7 |
References
- https://github.com/mg7-x/CVEs/blob/main/CVE-2025-61417/README.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-61417?
How severe is CVE-2025-61417?
How do I fix CVE-2025-61417?
Are you affected by CVE-2025-61417?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
