CVE-2025-10388
LOWSelleo Mentingo 2025.08.27 - Cross-Site Scripting via Create New Course Description Parameter
Title source: llmDescription
A vulnerability was identified in Selleo Mentingo 2025.08.27. This issue affects some unknown processing of the file /api/course/enroll-course of the component Create New Course Basic Settings. Such manipulation of the argument Description leads to cross site scripting. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
References (4)
Core 4
Core References
Permissions Required, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.323823
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.323823
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.643623
Various Sources exploit
https://gist.github.com/KhanMarshaI/584ae9d7ba8578ac040a0f89597fc3c1
Scores
CVSS v3
3.5
EPSS
0.0023
EPSS Percentile
13.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
CWE-94
Status
published
Products (1)
Selleo/Mentingo
2025.08.27
Published
Sep 14, 2025
Tracked Since
Feb 18, 2026