Junglewise Threat Intelligence

CVE-2025-6050: Mezzanine CMS stored XSS in displayable_links_js function

CVE-2025-6050 · Severity: medium · CVSS 4 · Published 2025-06-17

Technologies: Stephenmcd Mezzanine CMS, Mezzanine (PyPI). Vendors: PyPI.

Executive brief

Mezzanine CMS, a content management system platform, contains a security flaw in its administrative interface. An attacker with administrative privileges can create a blog post with a malicious title that, when viewed by another administrator, executes unauthorized code in their web browser. This could allow an attacker to perform actions on behalf of other administrators or access sensitive information within the management console.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Mezzanine CMS versions prior to 6.1.1. The flaw is located in the 'displayable_links_js' function within 'mezzanine/core/views.py', which fails to properly sanitize blog post titles before including them in JSON responses served via the '/admin/displayable_links.js' endpoint. An authenticated attacker with high privileges (admin) can inject a malicious JavaScript payload into a blog post title. If another administrator is tricked into visiting the affected endpoint, the payload executes in their browser context. The issue was addressed in version 6.1.1 by implementing proper escaping of the title field.

Affected products

  • stephenmcd Mezzanine CMS < 6.1.1

Timeline

  • 2025-05-21: disclosed: Initial outreach by Checkmarx researchers on GitHub discussions
  • 2025-06-17: advisory: GitHub Advisory and NVD entry published
  • 2025-06-17: patched: Fix released in version 6.1.1

References

Related threats