{"id":"CVE-2025-10909","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-10909","summary":"A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation…","details":"A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.","published":"2025-09-24T17:15:40.123","modified":"2026-06-17T08:29:15.450","cvss":{"score":2.4,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://karinagante.github.io/cve-2025-10909/"},{"type":"WEB","url":"https://karinagante.github.io/cve-2025-10909/#proof-of-concept-poc"},{"type":"WEB","url":"https://vuldb.com/?ctiid.325696"},{"type":"WEB","url":"https://vuldb.com/?id.325696"},{"type":"WEB","url":"https://vuldb.com/?submit.651379"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T08:29:15.450"}}