GHSA-4vrf-42cm-7xfw

Suggest an improvement
Source
https://github.com/advisories/GHSA-4vrf-42cm-7xfw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-4vrf-42cm-7xfw/GHSA-4vrf-42cm-7xfw.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-4vrf-42cm-7xfw
Aliases
Published
2025-10-20T15:30:25Z
Modified
2025-10-20T20:43:01.931650Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P CVSS Calculator
Summary
TastyIgniter vulnerable to Cross-Site Scripting
Details

Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.

Database specific
{
    "nvd_published_at": "2025-10-20T15:15:33Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-20T20:04:18Z",
    "severity": "LOW"
}
References

Affected packages

Packagist / tastyigniter/tastyigniter

Package

Name
tastyigniter/tastyigniter
Purl
pkg:composer/tastyigniter/tastyigniter

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.7.7

Affected versions

v0.*
v0.5.0
v1.*
v1.0.0
v1.1.0
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
2.*
2.1.0-rc.1
2.1.0-rc.2
2.1.0
2.1.1
v3.*
v3.0.4-beta
v3.0.4-beta.2
v3.0.4-beta.3
v3.0.4-beta.4
v3.0.4-beta.5
v3.0.4-beta.6
v3.0.4-beta.7
v3.0.4-beta.8
v3.0.4-beta.9
v3.0.4-beta.9.1
v3.0.4-beta.10
v3.0.4-beta.11
v3.0.4-beta.12
v3.0.4-beta.13
v3.0.4-beta.14
v3.0.4-beta.15
v3.0.4-beta.16
v3.0.4-beta.17
v3.0.4-beta.18
v3.0.4-beta.19
v3.0.4-beta.20
v3.0.4-beta.20.1
v3.0.4-beta.21
v3.0.4-beta.22
v3.0.4-beta.22.1
v3.0.4-beta.22.2
v3.0.4-beta.22.3
v3.0.4-beta.22.4
v3.0.4-beta.23
v3.0.4-beta.23.1
v3.0.4-beta.23.2
v3.0.4-beta.24
v3.0.4-beta.24.1
v3.0.4-beta.24.2
v3.0.4-beta.24.3
v3.0.4-beta.24.4
v3.0.4-beta.25
v3.0.4-beta.25.1
v3.0.4-beta.25.2
v3.0.4-beta.26
v3.0.4-beta.27
v3.0.4-beta.28
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.1.0-rc.1
v3.1.0
v3.1.1
v3.1.2
v3.2.0
v3.2.1
v3.2.2
v3.3.0
v3.3.1
v3.3.2
v3.4.0
v3.4.1
v3.5.0
v3.5.1
v3.5.2
v3.5.3
v3.5.4
v3.5.5
v3.6.0
v3.6.1
v3.6.3
v3.6.4
v3.6.5
v3.6.6
v3.6.7
v3.6.8
v3.6.9
v3.7.0
v3.7.1
v3.7.2
v3.7.3
v3.7.4
v3.7.5
v3.7.6
v3.7.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-4vrf-42cm-7xfw/GHSA-4vrf-42cm-7xfw.json"