CVE-2025-56515 is a high-severity file upload vulnerability affecting Fiora chat application versions 1.0.0 and earlier. Attackers can upload malicious SVG files containing embedded JavaScript via the user avatar functionality due to insufficient content validation. This allows for arbitrary JavaScript execution, leading to session hijacking, cookie theft, and unauthorized actions in the context of users viewing compromised profiles. While rated with a CVSS score of 8.8 (HIGH) and a FAUCET Risk Score of 83/100, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:suisuijiang:fiora:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.