VYPR
Medium severity5.4NVD Advisory· Published Jun 9, 2025· Updated Jun 17, 2026

CVE-2025-45055

CVE-2025-45055

Description

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Silverpeas/Silverpeascpe-rescue3 versions
    (expand)+ 2 more
    • (no CPE)
    • (no CPE)range: =6.4.2
    • cpe:2.3:a:silverpeas:silverpeas:6.4.2:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.