Cross-Site Scripting Vulnerability in TastyIgniter by TastyIgniter
CVE-2025-61417

8.8HIGH

Key Information:

Vendor
CVE Published:
20 October 2025

What is CVE-2025-61417?

A Cross-Site Scripting (XSS) vulnerability has been identified in TastyIgniter version 3.7.7, specifically within the /admin/media_manager component. This vulnerability allows attackers to upload an SVG file embedded with malicious JavaScript code. When an administrator attempts to preview this file, the malicious script executes within the administrator's browser context. This can potentially enable attackers to perform unauthorized actions, including altering admin account credentials and gaining control over admin functionalities. It is essential for users of TastyIgniter to promptly update their installations and implement security best practices to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61417 : Cross-Site Scripting Vulnerability in TastyIgniter by TastyIgniter