Sploitus

CVE-2025-10353

5 known exploits for CVE-2025-10353

File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter.

CVSS 4.0
9.3 CRITICAL
EPSS
2.5% (83th percentile)
Weakness
CWE-43
NVD status
Deferred
Published
2025-10-08

Fix

The vulnerability has been fixed by the Melis Technology team in the melis-cms v5.3.4, melis-core v5.3.11, and melis-cms-slider v.5.3.1 modules.

CVE-2025-10353 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2025-10353

Proof-of-concept code and exploit modules indexed by Sploitus