Laravel Translation Manager is a package to manage Laravel translation files. Prior to version 0.6.8, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data. An attacker can inject arbitrary HTML code, including JavaScript scripts, into the page processed by the user's browser, allowing them to steal sensitive data, hijack user sessions, or conduct other malicious activities. Only authenticated users with access to the translation manager are impacted. The issue is fixed in version 0.6.8.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-17461 Laravel Translation Manager Vulnerable to Stored Cross-site Scripting
Github GHSA Github GHSA GHSA-j226-63j7-qrqh Laravel Translation Manager Vulnerable to Stored Cross-site Scripting
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00057}

epss

{'score': 0.00062}


Mon, 09 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
Description Laravel Translation Manager is a package to manage Laravel translation files. Prior to version 0.6.8, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data. An attacker can inject arbitrary HTML code, including JavaScript scripts, into the page processed by the user's browser, allowing them to steal sensitive data, hijack user sessions, or conduct other malicious activities. Only authenticated users with access to the translation manager are impacted. The issue is fixed in version 0.6.8.
Title Laravel Translation Manager Vulnerable to Stored Cross-site Scripting
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-06-09T14:07:51.774Z

Reserved: 2025-06-02T10:39:41.633Z

Link: CVE-2025-49130

cve-icon Vulnrichment

Updated: 2025-06-09T14:07:47.944Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-09T13:15:23.977

Modified: 2025-06-12T16:06:47.857

Link: CVE-2025-49130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses