CVE-2025-6050

Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post titles before including them in JSON responses served via "/admin/displayable_links.js". An authenticated admin user can create a blog post with a malicious JavaScript payload in the title field, then trick another admin user into clicking a direct link to the "/admin/displayable_links.js" endpoint, causing the malicious script to execute in their browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jupo:mezzanine:*:*:*:*:*:*:*:*

History

30 Jul 2025, 19:09

Type Values Removed Values Added
CPE cpe:2.3:a:jupo:mezzanine:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
First Time Jupo
Jupo mezzanine
References () https://advisory.checkmarx.net/advisory/CVE-2025-6050/ - () https://advisory.checkmarx.net/advisory/CVE-2025-6050/ - Exploit, Third Party Advisory
References () https://github.com/stephenmcd/mezzanine/commit/898630d8df48cf3ddb8b9942f59168b93216e3f8 - () https://github.com/stephenmcd/mezzanine/commit/898630d8df48cf3ddb8b9942f59168b93216e3f8 - Patch
References () https://github.com/stephenmcd/mezzanine/discussions/2080 - () https://github.com/stephenmcd/mezzanine/discussions/2080 - Issue Tracking

14 Jul 2025, 12:15

Type Values Removed Values Added
Summary
  • (es) Mezzanine CMS, en versiones anteriores a la 6.1.1, contiene una vulnerabilidad de Cross-Site Scripting (XSS) Almacenado en la interfaz de administración. La vulnerabilidad se encuentra en la función "displayable_links_js", que no depura correctamente los títulos de las entradas del blog antes de incluirlos en las respuestas JSON enviadas a través de "/admin/displayable_links.js". Un usuario administrador autenticado puede crear una entrada de blog con una carga maliciosa de JavaScript en el campo de título y luego engañar a otro usuario administrador para que haga clic en un enlace directo al endpoint "/admin/displayable_links.js", lo que provoca la ejecución del script malicioso en su navegador.
References
  • {'url': 'https://https://github.com/stephenmcd/mezzanine/commit/898630d8df48cf3ddb8b9942f59168b93216e3f8', 'source': '596c5446-0ce5-4ba2-aa66-48b3b757a647'}
  • () https://advisory.checkmarx.net/advisory/CVE-2025-6050/ -
  • () https://github.com/stephenmcd/mezzanine/commit/898630d8df48cf3ddb8b9942f59168b93216e3f8 -

17 Jun 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 11:15

Updated : 2025-07-30 19:09


NVD link : CVE-2025-6050

Mitre link : CVE-2025-6050

CVE.ORG link : CVE-2025-6050


JSON object : View

Products Affected

jupo

  • mezzanine
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')