Vulnerability Description
Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The application fails to properly validate the MIME type and sanitize image metadata.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Doist | Todoist | 8484 |
Related Weaknesses (CWE)
References
- https://github.com/ASencerK/TodoistStoredXSSExploit
- https://github.com/echoBRT/TodoistStoredXSSExploit
- https://github.com/echoBRT/TodoistStoredXSSExploit
FAQ
What is CVE-2025-57292?
CVE-2025-57292 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The application fails to properly validate the MIME type and sanitize image metadata.
How severe is CVE-2025-57292?
CVE-2025-57292 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-57292?
Check the references section above for vendor advisories and patch information. Affected products include: Doist Todoist.