CVE-2025-49130

MEDIUM

laravel-translation-manager < 0.6.8 - Authenticated Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Laravel Translation Manager is a package to manage Laravel translation files. Prior to version 0.6.8, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data. An attacker can inject arbitrary HTML code, including JavaScript scripts, into the page processed by the user's browser, allowing them to steal sensitive data, hijack user sessions, or conduct other malicious activities. Only authenticated users with access to the translation manager are impacted. The issue is fixed in version 0.6.8.

Scores

CVSS v4 6.0
EPSS 0.0035
EPSS Percentile 27.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
barryvdh/laravel-translation-manager 0 - 0.6.8Packagist
barryvdh/laravel-translation-manager < 0.6.8
Published Jun 09, 2025
Tracked Since Feb 18, 2026