Логотип exploitDog
bind:CVE-2024-25637
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-25637

Количество 2

Количество 2

nvd логотип

CVE-2024-25637

больше 1 года назад

October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool. This issue has been patched in version 3.5.15.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-rjw8-v7rr-r563

больше 1 года назад

October System module has a Reflected XSS via X-October-Request-Handler Header

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-25637

October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool. This issue has been patched in version 3.5.15.

CVSS3: 3.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-rjw8-v7rr-r563

October System module has a Reflected XSS via X-October-Request-Handler Header

CVSS3: 3.1
1%
Низкий
больше 1 года назад

Уязвимостей на страницу