PT-2026-64876 · Unknown · Tastyigniter
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
TastyIgniter version 4.3.0
Description
A stored Cross-Site Scripting (XSS) issue exists in the Media Manager file upload functionality due to insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When an administrator views the file, the code executes within their browser session. This can be combined with a Cross-Site Request Forgery (CSRF) attack—a technique used to trick a user into executing unwanted actions on a web application—to extract the administrator's CSRF token and perform unauthorized actions, such as modifying credentials, to gain full administrative control.
Recommendations
Update TastyIgniter version 4.3.0 to a newer version that addresses this issue.
As a temporary mitigation, restrict the ability of low-privileged users to upload SVG files to the Media Manager.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tastyigniter