PT-2017-13966 · October · October Cms

Ishaq Mohammed

·

Publicado

2017-10-12

·

Atualizado

2022-05-13

·

CVE-2017-15284

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OctoberCMS version 1.0.425
Description The issue allows a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the context of the Admin account.
Recommendations For OctoberCMS version 1.0.425, consider restricting the upload of SVG files or disabling the ability to set custom Avatars until a fix is available. Additionally, restrict access to the profile management feature to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15284
GHSA-GVGF-FP4M-2HW6

Produtos afetados

October Cms