Vulnerability Description
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter.
Related Weaknesses (CWE)
References
- https://github.com/ivansmc00/CVE-2025-10353-POC
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-meli
FAQ
What is CVE-2025-10353?
CVE-2025-10353 is a documented vulnerability. File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST re...
How severe is CVE-2025-10353?
CVSS scoring is not yet available for CVE-2025-10353. Check NVD for updates.
Is there a patch for CVE-2025-10353?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.