CVE-2025-51488
EUVD-2025-2518119.08.2025, 15:15
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to store and execute arbitrary JavaScript by including a malicious HTML payload in the Name parameter when creating a new Admin.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| moonshine | moonshine | 𝑥 < 3.12.5 |
𝑥
= Vulnerable software versions