CVE-2025-10353
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter.
- Affected products
- Melis Platform, Melis-Cms-Slider
- CVSS 4.0
- 9.3 CRITICAL
- EPSS
- 2.5% (83th percentile)
- Weakness
- CWE-43
- NVD status
- Deferred
- Published
- 2025-10-08
Fix
The vulnerability has been fixed by the Melis Technology team in the melis-cms v5.3.4, melis-core v5.3.11, and melis-cms-slider v.5.3.1 modules.
CVE-2025-10353 at NVD
5 known exploits for CVE-2025-10353
Proof-of-concept code and exploit modules indexed by Sploitus