CVE-2025-50481
MEDIUMMezzanine CMS 6.1.0 - Stored Cross-Site Scripting via Blog Post Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-50481. PoCs published by Kevin Dicks, kevinpdicks.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Mezzanine CMS 6.1.0 via the /blog/blogpost/add component. Attackers can inject malicious JavaScript into a blog post, which executes when viewed by other users.
Description
A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a blog post.
Exploits (2)
This exploit demonstrates a stored XSS vulnerability in Mezzanine CMS 6.1.0 via the /blog/blogpost/add component. Attackers can inject malicious JavaScript into a blog post, which executes when viewed by other users.
This repository provides a detailed technical analysis of a stored XSS vulnerability in Mezzanine CMS v6.1.0, including step-by-step exploitation via crafted blog posts. It includes screenshots and confirms the vulnerability's impact while noting limitations (e.g., HttpOnly cookies prevent session hijacking).
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N