CVE-2025-10353 is a critical remote code execution vulnerability in the "melis-cms-slider" module of Melis Technology's Melis Platform. The flaw is exposed through the file upload functionality handled by the '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' endpoint, where attacker-controlled content can be submitted via the 'mcsdetail_img' parameter. According to the provided content, exploitation consists of uploading a malicious file through this POST request, after which the uploaded file can be executed remotely. The weakness is categorized as CWE-43. No specific vulnerable function implementation details or complete affected version range are provided in the source content, but the advisory confirms the issue affects Melis Platform installations and is remediated in melis-cms-slider v5.3.1 or later.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a minimal proof-of-concept for CVE-2025-10353 consisting of (1) a raw HTTP multipart/form-data request (CVE-2025-10353-POC.txt) and (2) a one-line README. The PoC targets a Melis CMS endpoint in the MelisCmsSlider module: POST /melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm. It attempts to exploit an unsafe/unrestricted file upload by submitting a file part named mcsdetail_img with filename "shell.php" and PHP content implementing a simple webshell that executes arbitrary OS commands via system($_POST['cmd']). If the upload is accepted and the server stores the file in a web-accessible, PHP-executable location, the attacker gains remote command execution by sending POST requests to the uploaded shell with parameter cmd. No automation, target discovery, or authentication handling is included; it is a manual request template intended to be replayed with a tool like Burp/Repeater or curl.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.