CVE-2025-10353: Missing Authorization vulnerability in Melis Platform
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetailimg' parameter.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10353?
CVE-2025-10353 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-10353?
To mitigate CVE-2025-10353, update the Melis Platform or the melis-cms-slider module to the latest version provided by Melis Technology.
What are the potential impacts of CVE-2025-10353?
CVE-2025-10353 can lead to unauthorized remote code execution, allowing attackers to perform malicious activities on the affected server.
Which versions of Melis Platform are affected by CVE-2025-10353?
CVE-2025-10353 affects all versions of the Melis Platform that include the vulnerable melis-cms-slider module.
Is CVE-2025-10353 exploitable through common web requests?
Yes, CVE-2025-10353 can be exploited through a crafted POST request to the specified endpoint.