CVE-2025-62415 | Bagisto up to 2.3.7 TinyMCE Image Upload cross site scripting (GHSA-67px-r26w-598x / EUVD-2025-34810)
A vulnerability was found in Bagisto up to 2.3.7. It has been classified as problematic. This impacts an unknown function of the component TinyMCE Image Upload. The manipulation leads to basic cross site scripting.
This vulnerability is referenced as CVE-2025-62415. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.