CVE-2025-51488
19.08.2025, 15:15
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to store and execute arbitrary JavaScript by including a malicious HTML payload in the Name parameter when creating a new Admin.
Vendor | Product | Version |
---|---|---|
moonshine | moonshine | 𝑥 < 3.12.5 |
𝑥
= Vulnerable software versions