PT-2020-18387 · October · October Cms

Sivanesh Ashok

+1

·

Published

2020-06-03

·

Updated

2022-06-30

·

CVE-2020-5298

CVSS v3.1

4.0

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OctoberCMS versions 1.0.319 through 1.0.465
Description A user with the ability to use the import functionality of the ImportExportController behavior can be socially engineered by an attacker to upload a maliciously crafted CSV file, which could result in a reflected XSS attack on the user in question.
Recommendations For versions 1.0.319 through 1.0.465, update to Build 466 (v1.0.466) to resolve the issue. As a temporary workaround, apply the patch from https://github.com/octobercms/october/commit/cd0b6a791f995d86071a024464c1702efc50f46c to your installation manually if unable to upgrade to Build 466.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5298
GHSA-GG6X-XX78-448C

Affected Products

October Cms