CVE-2025-51488 is a Stored Cross-Site Scripting (XSS) vulnerability affecting MoonShine versions prior to 3.12.4. This flaw allows a highly privileged attacker to inject and execute arbitrary JavaScript by embedding a malicious HTML payload within the "Name" parameter during the creation of a new Admin user. While the CVSS score is 4.9 (Medium) due to high privileges required for exploitation, a successful attack could lead to high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.12.5CPE matchmatch criteria | cpe:2.3:a:moonshine:moonshine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.