CVE-2025-61417
TastyIgniter vulnerable to Cross-Site Scripting
EPSS 0.55%
Description
Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.
How to fix CVE-2025-61417
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Packagist/tastyigniter/tastyigniter—no fix listed
Is CVE-2025-61417 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, <= 3.7.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P |