Количество 2
Количество 2
CVE-2023-44383
October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the media manager when SVG files are supported. This issue has been patched in version 3.5.2.
GHSA-rvx8-p3xp-fj3p
October CMS stored XSS by authenticated backend user with improper configuration
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-44383 October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the media manager when SVG files are supported. This issue has been patched in version 3.5.2. | CVSS3: 5.4 | 1% Низкий | около 2 лет назад | |
GHSA-rvx8-p3xp-fj3p October CMS stored XSS by authenticated backend user with improper configuration | CVSS3: 5.4 | 1% Низкий | около 2 лет назад |
Уязвимостей на страницу