A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Sep 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mangati
Mangati novosga |
|
Vendors & Products |
Mangati
Mangati novosga |
Wed, 24 Sep 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Mangati NovoSGA SVG File admin cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-09-24T16:32:06.892Z
Updated: 2025-09-24T16:32:06.892Z
Reserved: 2025-09-24T10:21:41.685Z
Link: CVE-2025-10909

No data.

Status : Awaiting Analysis
Published: 2025-09-24T17:15:40.123
Modified: 2025-09-24T18:11:24.520
Link: CVE-2025-10909

No data.