CVE-2015-5612
EPSS 0.26%October CMS XSS In Caption Tag of Profile
Published: 5/17/2022Modified: 11/8/2023
Also known as:GHSA-9hq8-v2jc-qj4r
Description
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via the caption tag of a profile image.
Affected packages (1)
- Packagist/october/octoberfrom 0, < 1.0.319
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2015-5612
- WEBhttps://github.com/octobercms/october/commit/8a4ac533e5cd6b8f92e9ef19fbfbb2f505dc7a9a
- WEBhttps://github.com/octobercms/october/issues/1302
- WEBhttp://www.openwall.com/lists/oss-security/2015/07/21/5
- WEBhttp://www.openwall.com/lists/oss-security/2015/07/22/3