CVE-2025-10353: Melis Technology Melis Platform
Critical severity, CVSS 9.3. EPSS: 2.7% chance of exploitation in the next 30 days.
File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter.
Affected products
- Melis Technology Melis Platform: before 5.3.1 (fixed in 5.3.1)
Published 2025-10-08. Last modified 2026-10-08.