216.73.216.6

CVE-2025-10353

· Published 08/10/2025 11:15 · Modified 08/10/2025 19:38

Labels: CVE-2025-10353 2025-10-08CVE-2025-10353CWE-43[email protected]

Essential information

Published
08/10/2025 11:15
Modified
08/10/2025 19:38
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
melis technology / melis platform cpe:2.3:a:melis_technology:melis_platform:*:*:*:*:*:*:*:*
melis technology / melis cms slider cpe:2.3:a:melis_technology:melis_cms_slider:*:*:*:*:*:*:*:*

References