CVE 8.3 HIGH

CVE-2025-60880_CVE-2025-60880

8.3 / 10
HIGH
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:L/PR:H/S:C/UI:R

Description

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions.

Basic Information

ID CVE-2025-60880
Source mitre
Published Oct 10, 2025 at 00:00
Modified Oct 10, 2025 at 18:59

Affected Product

Vendor n/a
Product n/a
Version n/a
Affected Versions n/a n/a n/a

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.