Description
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the context of the Admin account.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6741 | OctoberCMS Cross-Site Scripting |
Github GHSA |
GHSA-gvgf-fp4m-2hw6 | OctoberCMS Cross-Site Scripting |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:50:16.434Z
Reserved: 2017-10-12T00:00:00.000Z
Link: CVE-2017-15284
No data.
Status : Deferred
Published: 2017-10-12T08:29:00.570
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-15284
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA