CVE-2026-14856
MEDIUMStored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-14856. PoCs published by jonas-fernandez-as.
AI-analyzed exploit summary The repository claims to detail a stored XSS to account takeover vulnerability in TastyIgniter v4.3.0 (CVE-2026-14856) but does not include exploit code or technical breakdown. Instead, it references an external PDF for the 'full technical report,' which is a common social engineering tactic to lure researchers into downloading files from untrusted sources.
Description
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When an administrator views that file, the code executes in the context of their browser. By chaining this vulnerability with a Cross-Site Request Forgery (CSRF) attack, an attacker can extract the administrator’s CSRF token and perform unauthorized actions—such as modifying credentials—thereby gaining full control of the administrative account.
Exploits (1)
The repository claims to detail a stored XSS to account takeover vulnerability in TastyIgniter v4.3.0 (CVE-2026-14856) but does not include exploit code or technical breakdown. Instead, it references an external PDF for the 'full technical report,' which is a common social engineering tactic to lure researchers into downloading files from untrusted sources.
References (1)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X