Cross-Site Scripting Vulnerability in Galette Membership Management Application
CVE-2025-48076
5.3MEDIUM
What is CVE-2025-48076?
The Galette membership management application, designed for non-profit organizations, presents a vulnerability that allows malicious users to exploit cross-site scripting (XSS). Specifically, versions 1.1.5.2 and below enable users to edit group names, thereby inserting an XSS payload. This significantly compromises the security of the application. Users are encouraged to upgrade to version 1.2.0 or later to mitigate against this vulnerability.
Affected Version(s)
galette < 1.2.0
