Security Advisory

CVE-2025-62798

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-28 20:58:21
Last updated 2025-10-29 17:31:24
Assigner GitHub_M
CVSS score 5.4
State PUBLISHED

Description

Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }} were evaluated by Vue. This allowed attackers to inject arbitrary JavaScript or HTML that executes in the browser when the field is displayed. The issue has been fixed in v9.11.1 .