CVE-2025-70842: XSS
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted SVG files containing malicious JavaScript code. Once uploaded, the script executes in the browser of any user who accesses the direct URL of the image, including unauthenticated visitors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70842?
The severity of CVE-2025-70842 is medium with a CVSS score of 5.4.
How do I fix CVE-2025-70842?
To fix CVE-2025-70842, ensure that you are using an updated version of FluentCMS that addresses the stored XSS vulnerability.
What type of vulnerability is CVE-2025-70842?
CVE-2025-70842 is a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2025-70842?
Authenticated administrators of FluentCMS 1.2.3 are affected by CVE-2025-70842.
What are the potential risks of CVE-2025-70842?
CVE-2025-70842 could allow the execution of malicious JavaScript in the browsers of users accessing crafted SVG files.