← back
CVE-2025-61417

CVE-2025-61417

CVSS 8.8 HIGHEPSS 0.5%CWE-434CWE-79
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
20 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a