CVE-2023-25365

HIGH7.8EPSS 0.05%

October CMS Cross-site Scripting vulnerability

Published: 2/9/2024Modified: 2/16/2024
Also known as:GHSA-gcgj-qh8p-57hm

Description

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References (3)