Home Embedded Vulns General Vulns

CVE-2020-5298

MEDIUM 4.0

Our Analysis: General Purpose

Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.

Published Date June 3, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be socially engineered by an attacker to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in question Issue has been patched in Build 466 (v1.0.466).

Potentially Affected Vendors