October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool. This issue has been patched in version 3.5.15.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-26T15:55:35.578Z
Updated: 2024-08-01T23:44:09.889Z
Reserved: 2024-02-08T22:26:33.513Z
Link: CVE-2024-25637
Vulnrichment
Updated: 2024-08-01T23:44:09.889Z
NVD
Status : Awaiting Analysis
Published: 2024-06-26T16:15:10.910
Modified: 2024-06-27T12:47:19.847
Link: CVE-2024-25637
Redhat
No data.