Junglewise Threat Intelligence

CVE-2025-29573: Mezzanine CMS persistent XSS in Forms module via malicious filename

CVE-2025-29573 · Severity: medium · CVSS 6.1 · Published 2025-05-05

Technologies: Mezzanine CMS, Mezzanine (PyPI). Vendors: Mezzanine, PyPI.

Executive brief

Mezzanine CMS, a popular content management platform built on Django, contains a security flaw in its form handling module. An attacker can upload a file with a specially crafted name that, when viewed by a site administrator, executes malicious code in their browser. This could allow an attacker to hijack administrative sessions or perform unauthorized actions on the website.

Technical details

A persistent cross-site scripting (XSS) vulnerability exists in Mezzanine CMS versions 6.0.0 and earlier. The flaw is located within the 'View Entries' feature of the Forms module, where the application fails to properly neutralize user-controllable input—specifically malicious filenames—before rendering them in the administrative interface. An unauthenticated attacker can exploit this by submitting a form with a crafted filename. When an administrator views the submitted entries, the malicious script executes in their security context. This is tracked as CWE-79 and has a CVSS score of 6.1 due to the required user interaction and scope change.

Affected products

  • Mezzanine Mezzanine CMS <= 6.0.0

Timeline

  • 2025-05-05: disclosed
  • 2025-05-05: advisory

References

Related threats