PT-2024-21149 · Octobercms · October Cms Bloghub Plugin

Prateek Kuber

·

Published

2024-08-16

·

Updated

2024-10-30

·

CVE-2024-25837

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions October CMS Bloghub Plugin versions 1.3.8 and lower
Description A stored cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section. This can lead to the execution of malicious code on the victim's browser.
Recommendations For October CMS Bloghub Plugin versions 1.3.8 and lower, update to a version higher than 1.3.8 to resolve the issue. As a temporary workaround, consider disabling the Comments section until a patch is available. Restrict access to the Comments section to minimize the risk of exploitation. Avoid using the Comments section in the affected plugin until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-25837

Affected Products

October Cms Bloghub Plugin