Aller au contenu

Fiche vulnérabilité

CVE-2025-13415 : faille moyenne easyimages2.0 project easyimages2.0 (CVSS 5.4)

Description

A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image Handler. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
19 nov. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • easyimages2.0 project easyimages2.0

Références

Rechercher une autre vulnérabilité dans la base CVE