CVE-2017-1000193

MEDIUM6.1EPSS 0.40%

October CMS XSS

Published: 5/13/2022Modified: 2/16/2024
Also known as:GHSA-3p6c-9xhm-8x7h

Description

October CMS build 412 is vulnerable to stored XSS in brand logo image name resulting in JavaScript code execution in the victim's browser.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (3)