« Volver al listado

CVE-2025-62798

Estado: AplazadaMedia (5.4)—

Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }} were evaluated by Vue. This allowed attackers to inject arbitrary JavaScript or HTML that executes in the browser when the field is displayed. The issue has been fixed in v9.11.1 .

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-62798",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-62798",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-10-29T17:31:18.507828Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "code16",
          "product": "sharp",
          "versions": [
            {
              "status": "affected",
              "version": "< 9.11.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-10-28T21:15:40.913",
  "references": [
    {
      "url": "https://github.com/code16/sharp/pull/654",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/code16/sharp/releases/tag/v9.11.1",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/code16/sharp/security/advisories/GHSA-9f58-4465-23c7",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }} were evaluated by Vue. This allowed attackers to inject arbitrary JavaScript or HTML that executes in the browser when the field is displayed. The issue has been fixed in v9.11.1 ."
    },
    {
      "lang": "es",
      "value": "Sharp es un framework de gestión de contenido construido para Laravel como un paquete. Antes de la versión 9.11.1, una vulnerabilidad de Cross-Site Scripting (XSS) fue descubierta en code16/sharp al renderizar contenido usando el componente SharpShowTextField. En las versiones afectadas, las expresiones envueltas en {{ & }} eran evaluadas por Vue. Esto permitía a los atacantes inyectar JavaScript o HTML arbitrario que se ejecuta en el navegador cuando se muestra el campo. El problema ha sido solucionado en la v9.11.1."
    }
  ],
  "lastModified": "2026-09-30T23:10:00.237",
  "sourceIdentifier": "security-advisories@github.com"
}