Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2g8p-j2r6-vqpj

Опубликовано: 28 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Withdrawn Advisory: October Cross-site Scripting vulnerability

Withdrawn Advisory

This advisory has been withdrawn because the vulnerability affects October CMS's installer, not October CMS. The installer deletes all folders and files upon completion of installation. The vulnerability is valid, but because October's installer is not part of one of the GitHub Advisory Database's supported ecosystems, alerts cannot be sent out for the correct package.

Corrected Description

A Cross-Site Scripting (XSS) vulnerability in the installer of October CMS allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.

Пакеты

Наименование

october/cms

composer
Затронутые версииВерсия исправления

<= 3.4.16

Отсутствует

EPSS

Процентиль: 49%
0.00261
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.

EPSS

Процентиль: 49%
0.00261
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79