VYPR
Medium severity6.1NVD Advisory· Published Oct 3, 2025· Updated Jun 17, 2026

CVE-2025-60450

CVE-2025-60450

Description

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\editor\Uploader.class.php component. This security flaw allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed.

Affected products

3
  • Metinfo/Metinfollm-fuzzy2 versions
    8.0+ 1 more
    • (no CPE)range: 8.0
    • cpe:2.3:a:metinfo:metinfo:8.0.0:*:*:*:*:*:*:*
  • MetInfo/CMSdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.