Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hxpp-g76m-qhvg | October allows an admin account to upload PDF containing malicious JavaScript |
Wed, 02 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Octobercms
Octobercms october |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:octobercms:october:3.6.30:*:*:*:*:*:*:* | |
| Vendors & Products |
Octobercms
Octobercms october |
|
| Metrics |
cvssV3_1
|
Wed, 02 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-02T20:35:08.391Z
Reserved: 2024-09-11T00:00:00.000Z
Link: CVE-2024-45962
Updated: 2024-10-02T20:34:18.037Z
Status : Analyzed
Published: 2024-10-02T20:15:11.153
Modified: 2025-09-29T17:30:04.620
Link: CVE-2024-45962
No data.
OpenCVE Enrichment
No data.
Github GHSA