CVE-2025-10909 | Mangati NovoSGA up to 2.2.9 SVG File /admin logoNavbar/logoLogin cross site scripting (EUVD-2025-31011)
A vulnerability classified as problematic has been found in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting.
This vulnerability is known as CVE-2025-10909. Remote exploitation of the attack is possible. Furthermore, an exploit is available.