Cross-Site Scripting Vulnerability in TastyIgniter by TastyIgniter
CVE-2025-61417
8.8HIGH
What is CVE-2025-61417?
A Cross-Site Scripting (XSS) vulnerability has been identified in TastyIgniter version 3.7.7, specifically within the /admin/media_manager component. This vulnerability allows attackers to upload an SVG file embedded with malicious JavaScript code. When an administrator attempts to preview this file, the malicious script executes within the administrator's browser context. This can potentially enable attackers to perform unauthorized actions, including altering admin account credentials and gaining control over admin functionalities. It is essential for users of TastyIgniter to promptly update their installations and implement security best practices to mitigate the risks associated with this vulnerability.