Cross-site scripting in October CMS - #VU149490

 

Cross-site scripting in October CMS - #VU149490

Published: September 14, 2026


Vulnerability identifier: #VU149490
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the backend origin.

The vulnerability exists due to improper neutralization of input during web page generation in the backend Event Log preview\'s client-side exception beautifier when an administrator opens a log preview containing crafted brace tokens in an exception message. A remote privileged user can supply a logged exception message containing crafted brace tokens to execute arbitrary script in the backend origin.

The crafted payload remains persistent until the affected log entry is deleted.


Affected software

October CMS

Remediation

Install security update from vendor's website.

October CMS - addressed in versions 3.7.17, 4.2.23

External References

Related Security Bulletins