VYPR
Medium severity6.1NVD Advisory· Published Oct 3, 2025· Updated Jun 17, 2026

CVE-2025-60454

CVE-2025-60454

Description

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the image management module, specifically in the app\system\img\admin\img_admin.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Metinfo/Metinfollm-fuzzy2 versions
    8.0+ 1 more
    • (no CPE)range: 8.0
    • cpe:2.3:a:metinfo:metinfo:8.0.0:*:*:*:*:*:*:*
  • MetInfo/CMSdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.