PT-2020-14314 · October · October Cms
Hoan Hoang
·
Published
2020-11-23
·
Updated
2020-11-30
·
CVE-2020-15249
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
October CMS versions 1.0.319 through 1.0.468
Description
The issue allows backend users with access to upload files to upload SVG files without any sanitization applied to the uploaded files. Since SVG files support being parsed as HTML by browsers, this means that they could theoretically upload Javascript that would be executed on a path under the website's domain, but they would have to convince their target to visit that location directly in the target's browser. The backend does not display SVGs inline anywhere, and SVGs are only displayed as image resources in the backend and are thus unable to be executed.
Recommendations
For versions 1.0.319 through 1.0.468, update to Build 469 (v1.0.469) or v1.1.0 to resolve the issue.
As a temporary workaround, consider applying the patch from https://github.com/octobercms/library/commit/80aab47f044a2660aa352450f55137598f362aa4 to your installation manually if unable to upgrade to Build 469 or v1.1.0.
Restrict access to uploading SVG files until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
October Cms