PT-2024-21057 · October · October
Mayank Mehra
·
Published
2024-06-26
·
Updated
2024-06-27
·
CVE-2024-25637
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
October versions prior to 3.5.15
Description
The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this issue cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool.
Recommendations
For versions prior to 3.5.15, update to version 3.5.15 to resolve the issue. As a temporary workaround, consider restricting access to the X-October-Request-Handler Header to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
October