CVE-2017-15284
Summary
| CVE | CVE-2017-15284 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-12 08:29:00 UTC |
| Updated | 2020-08-03 12:15:00 UTC |
| Description | Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the context of the Admin account. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Octobercms | October | 1.0.425 | All | All | All |
| Application | Octobercms | October | 1.0.425 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Remove SVG from image types · octobercms/library@3bbbbf3 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| OctoberCMS 1.0.425 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| OctoberCMS 1.0.425 (Build 425) - Cross-Site Scripting | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.