October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect outside the scope of the active host. This vulnerability has been patched in version 3.5.15.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2165 | October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect outside the scope of the active host. This vulnerability has been patched in version 3.5.15. |
Github GHSA |
GHSA-v2vf-jv88-3fp5 | October System module has an Open Redirect for Administrator Accounts |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Sep 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Octobercms
Octobercms october |
|
| CPEs | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Octobercms
Octobercms october |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-01T23:28:12.102Z
Reserved: 2024-01-29T20:51:26.011Z
Link: CVE-2024-24764
Updated: 2024-08-01T23:28:12.102Z
Status : Modified
Published: 2024-06-26T01:15:47.890
Modified: 2024-11-21T08:59:39.267
Link: CVE-2024-24764
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA