CVE-2025-46198

Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element
Configurations

No configuration.

History

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) Cross Site Scripting en grav v.1.7.48, v.1.7.47 y v.1.7.46 permite a un atacante ejecutar código arbitrario a través del atributo onerror del elemento img.

25 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-25 20:15

Updated : 2025-07-29 14:14


NVD link : CVE-2025-46198

Mitre link : CVE-2025-46198

CVE.ORG link : CVE-2025-46198


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')