CVE-2025-45878,CVE-2025-45879 and CVE-2025-45880 Showcase

CVE-2025-45878,CVE-2025-45879 and CVE-2025-45880 Showcase


This blog post is written to showcase the three CVEs I discovered in the web application Amigdala 2.2.6 by Miliaris.
For this time, I'll stick with the Mitre Template, and I will avoid releasing any sensitive information.

CVE-2025-45878 (Mitre) (NVD)

[Suggested description]

A reflected cross-site scripting (XSS) vulnerability in the report manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload.

[Additional Information]

Vulnerable Parameter datasourceId

[Vulnerability Type]

Reflected Cross-Site Scripting (XSS)

[Vendor of Product]

Miliaris

[Affected Product Code Base]

Amigdala - 2.2.6

[Affected Component]

Amigdala web Application

[Attack Type]

Remote

[Impact Information Disclosure]

True

[CVE Impact Other]

Run Arbitrary Javascript code

[Attack Vectors]

Crafted URL

[Reference]

https://www.miliaris.it/

[Discoverer]

Marco Nappi


CVE-2025-45879 (Mitre) (NVD)

[Suggested description]

A reflected cross-site scripting (XSS) vulnerability in the e-mail manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload.

[Additional Information]

Vulnerable parameter reportEngineId

[Vulnerability Type]

Reflected Cross-Site Scripting (XSS)

[Vendor of Product]

Miliaris

[Affected Product Code Base]

Amigdala - 2.2.6

[Affected Component]

Amigdala web Application

[Attack Type]

Remote

[Impact Information Disclosure]

True

[CVE Impact Other]

Run Arbitrary JavaScript code

[Attack Vectors]

Crafted URL

[Reference]

https://www.miliaris.it/

[Discoverer]

Marco Nappi


CVE-2025-45880 (Mitre) (NVD)

[Suggested description]

A reflected cross-site scripting (XSS) vulnerability in the data resource management function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload.

[Additional Information]

Vulnerable Parameter mailSessionId

[Vulnerability Type]

Reflected Cross-Site Scripting (XSS)

[Vendor of Product]

Miliaris

[Affected Product Code Base]

Amigdala - 2.2.6

[Affected Component]

Amigdala web Application

[Attack Type]

Remote

[Impact Information Disclosure]

True

[CVE Impact Other]

Run Arbitrary JavaScript code

[Attack Vectors]

Crafted URL

[Reference]

https://www.miliaris.it/

[Has vendor confirmed or acknowledged the vulnerability?]

True

[Discoverer]

Marco Nappi

Commenti

Post popolari in questo blog

From SAST to CVE-2025-46337

Case of Study : Hide PowerUp.ps1 from MS Defender

Unveiling CVE-2024-44777, CVE-2024-44778, and CVE-2024-44779