CVE-2025-61417
Last modified
CVE-2025-61417 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tastyigniter | Tastyigniter | 3.7.7 |
References
- https://github.com/mg7-x/CVEs/blob/main/CVE-2025-61417/README.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-61417?
How severe is CVE-2025-61417?
How do I fix CVE-2025-61417?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6138A vulnerability classified as critical was found in TOTOLINK…8.8
- CVE-2025-61385SQL injection vulnerability in tlocke pg8000 1.31.4 allows r…9.6
- CVE-2025-6139A vulnerability, which was classified as problematic, has be…3.9
- CVE-2025-6140A vulnerability, which was classified as problematic, was fo…3.3
- CVE-2025-6141A vulnerability has been found in GNU ncurses up to 6.5-2025…4.8
- CVE-2025-61413A stored cross-site scripting (XSS) vulnerability in the /ma…6.1
- CVE-2025-6142A vulnerability was found in Intera InHire up to 20250530. I…6.3
- CVE-2025-61427A reflected cross-site scripting (XSS) vulnerability in BEO …6.1
- CVE-2025-61429An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 a…8.8
- CVE-2025-6143A vulnerability, which was classified as critical, was found…8.8
- CVE-2025-61430Improper handling of DNS over TCP in Simple DNS Plus v9 allo…6.5
- CVE-2025-61431A reflected cross-site scripted (XSS) vulnerability in the /…6.1
Are you affected by CVE-2025-61417?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
