Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the context of the Admin account.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6741 | OctoberCMS Cross-Site Scripting |
Github GHSA |
GHSA-gvgf-fp4m-2hw6 | OctoberCMS Cross-Site Scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:50:16.434Z
Reserved: 2017-10-12T00:00:00
Link: CVE-2017-15284
No data.
Status : Deferred
Published: 2017-10-12T08:29:00.570
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-15284
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA