October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the media manager when SVG files are supported. This issue has been patched in version 3.5.2.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3032 | October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the media manager when SVG files are supported. This issue has been patched in version 3.5.2. |
Github GHSA |
GHSA-rvx8-p3xp-fj3p | October CMS stored XSS by authenticated backend user with improper configuration |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 05 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-05T13:39:36.615Z
Reserved: 2023-09-28T17:56:32.612Z
Link: CVE-2023-44383
Updated: 2024-08-02T20:07:32.899Z
Status : Modified
Published: 2023-11-29T20:15:07.573
Modified: 2024-11-21T08:25:47.217
Link: CVE-2023-44383
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA