GHSA-4c44-r8rm-3p39

Suggest an improvement
Source
https://github.com/advisories/GHSA-4c44-r8rm-3p39
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-4c44-r8rm-3p39/GHSA-4c44-r8rm-3p39.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4c44-r8rm-3p39
Aliases
  • CVE-2025-10909
Published
2025-09-24T18:30:31Z
Modified
2025-09-24T23:41:39.143246Z
Severity
  • 2.4 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Mangati NovoSGA XSS vulnerability in /admin
Details

A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "severity": "LOW",
    "github_reviewed_at": "2025-09-24T20:10:39Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "nvd_published_at": "2025-09-24T17:15:40Z",
    "github_reviewed": true
}
References

Affected packages

Packagist / novosga/novosga

Package

Name
novosga/novosga
Purl
pkg:composer/novosga/novosga

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.2.9

Affected versions

v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.4.0
v1.4.1
v1.5.0
v1.5.1
v1.5.2
v2.*
v2.0.0-BETA1
v2.0.0-BETA2
v2.0.0-BETA3
v2.0.0-BETA4
v2.0.0-BETA5
v2.0.0-BETA6
v2.0.0-RC2
v2.0.0-RC3
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
v2.0.10
v2.0.11
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.8
v2.1.9
v2.2.0-beta.1
v2.2.0-beta.2
v2.2.0
v2.2.1
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
2.*
2.0.0-RC1
2.2.2
2.2.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-4c44-r8rm-3p39/GHSA-4c44-r8rm-3p39.json"