Description
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the context of the Admin account.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6741 | OctoberCMS Cross-Site Scripting |
Github GHSA |
GHSA-gvgf-fp4m-2hw6 | OctoberCMS Cross-Site Scripting |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:50:16.434Z
Reserved: 2017-10-12T00:00:00.000Z
Link: CVE-2017-15284
No data.
Status : Modified
Published: 2017-10-12T08:29:00.570
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-15284
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA