melisplatform/melis-cms-slider
MelisCmsSlider provides a full Slider system for Melis Platform, including templating plugins.
Activity
- Latest release
- 3w ago
- Total releases
- 34
- Cadence
- ~3 months
- Last 12 months
- 7
Reach
- Stars
- 1
Details
- License
- unknown
- First release
- May 16, 2017
| Version | Released | |
|---|---|---|
v6.0.3
patch
| ||
v6.0.2
patch
| ||
v6.0.1
patch
| ||
v6.0.0
major
| ||
v5.3.6
patch
| ||
v5.3.5
patch
| ||
v5.3.4
patch
| ||
v5.3.3
patch
| ||
v5.3.2
patch
| ||
v5.3.1
patch
| ||
v5.3.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.2.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.1.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.0.1
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.0.0
major
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v4.1.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v4.0.2
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v4.0.1
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v4.0.0
major
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v3.2.2
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v3.2.1
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v3.2.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v3.1.1
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v3.1.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v3.0.1
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v3.0.0
major
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v2.5.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v2.4.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v2.3.1
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v2.3.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v2.2.1
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v2.2.0
minor
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v2.1.1
patch
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v2.1
initial
1 CVE
CVE-2025-10353
GHSA-chw4-gjvw-3gxc
Oct 08, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
Network
Low
None
None
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.1.0
v3.1.1
+ 13 more Show less
v3.2.0
v3.2.1
v3.2.2
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.3.0
Fixed in
5.3.1
References
Updated Oct 09, 2025 · Source: OSV.dev |