Логотип exploitDog
bind:CVE-2025-61676
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-61676

Количество 2

Количество 2

nvd логотип

CVE-2025-61676

30 дней назад

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the stylesheet input at Styles from Branding & Appearance settings. A specially crafted input could break out of the intended <style> context, allowing arbitrary script execution across backend pages for all users. This issue has been patched in versions 3.7.13 and 4.0.12.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wvpq-h33f-8rp6

около 1 месяца назад

October CMS Vulnerable to Stored XSS via Branding Styles

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-61676

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the stylesheet input at Styles from Branding & Appearance settings. A specially crafted input could break out of the intended <style> context, allowing arbitrary script execution across backend pages for all users. This issue has been patched in versions 3.7.13 and 4.0.12.

CVSS3: 6.1
0%
Низкий
30 дней назад
github логотип
GHSA-wvpq-h33f-8rp6

October CMS Vulnerable to Stored XSS via Branding Styles

CVSS3: 6.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу