Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rjw8-v7rr-r563

Опубликовано: 26 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

October System module has a Reflected XSS via X-October-Request-Handler Header

Impact

The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool.

Patches

This issue has been patched in v3.5.15.

References

Credits to:

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

october/system

composer
Затронутые версииВерсия исправления

>= 3.2, < 3.5.15

3.5.15

EPSS

Процентиль: 74%
0.00821
Низкий

3.1 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.1
nvd
больше 1 года назад

October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool. This issue has been patched in version 3.5.15.

EPSS

Процентиль: 74%
0.00821
Низкий

3.1 Low

CVSS3

Дефекты

CWE-79