Cross Site Scripting Vulnerability Allows Local Attacker to Execute Arbitrary Code
CVE-2023-25365

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
8 February 2024

What is CVE-2023-25365?

A cross site scripting vulnerability exists in October CMS version 3.2.0 that poses significant security risks. This vulnerability allows local attackers to execute arbitrary code through a specific file type (.mp3) via a file upload mechanism. Users of affected versions should be aware of the potential for unauthorized access and the exploitation of this security flaw, which may lead to further complications within the web application environment. Immediate attention to patching and securing file upload features is advised to mitigate risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.