cve/2025/CVE-2025-51489.md
2025-09-29 21:09:30 +02:00

817 B

CVE-2025-51489

Description

A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upload a malicious SVG file when creating/updating an Article and correctly execute arbitrary JavaScript when the file link is opened.

POC

Reference

Github