SB2017101222 - Cross-site scripting in OctoberCMS October CMS



SB2017101222 - Cross-site scripting in OctoberCMS October CMS

Published: October 12, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017101222
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cross-site scripting (CVE-ID: CVE-2017-15284)

The vulnerability allows a remote authenticated user to read and manipulate data.

Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the context of the Admin account.


Remediation

Install update from vendor's website.