October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hxpp-g76m-qhvg October allows an admin account to upload PDF containing malicious JavaScript
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 02 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Octobercms
Octobercms october
Weaknesses CWE-79
CPEs cpe:2.3:a:octobercms:october:3.6.30:*:*:*:*:*:*:*
Vendors & Products Octobercms
Octobercms october
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Description October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-02T20:35:08.391Z

Reserved: 2024-09-11T00:00:00

Link: CVE-2024-45962

cve-icon Vulnrichment

Updated: 2024-10-02T20:34:18.037Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-02T20:15:11.153

Modified: 2025-09-29T17:30:04.620

Link: CVE-2024-45962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.