Stored Cross-Site Scripting October CMS
Moderate severity
GitHub Reviewed
Published
Jul 26, 2023
to the GitHub Advisory Database
•
Updated Nov 5, 2023
Description
Published by the National Vulnerability Database
Jul 26, 2023
Published to the GitHub Advisory Database
Jul 26, 2023
Reviewed
Jul 26, 2023
Last updated
Nov 5, 2023
An svg file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code in the context of a browser via a crafted svg file. Attackers must be authenticated as users.
References