Логотип exploitDog
bind:CVE-2024-24764
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-24764

Количество 2

Количество 2

nvd логотип

CVE-2024-24764

больше 1 года назад

October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect outside the scope of the active host. This vulnerability has been patched in version 3.5.15.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-v2vf-jv88-3fp5

больше 1 года назад

October System module has an Open Redirect for Administrator Accounts

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-24764

October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect outside the scope of the active host. This vulnerability has been patched in version 3.5.15.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-v2vf-jv88-3fp5

October System module has an Open Redirect for Administrator Accounts

CVSS3: 3.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу