Cross Site Scripting Vulnerability Allows Local Attacker to Execute Arbitrary Code
CVE-2023-25365
7.8HIGH
What is CVE-2023-25365?
A cross site scripting vulnerability exists in October CMS version 3.2.0 that poses significant security risks. This vulnerability allows local attackers to execute arbitrary code through a specific file type (.mp3) via a file upload mechanism. Users of affected versions should be aware of the potential for unauthorized access and the exploitation of this security flaw, which may lead to further complications within the web application environment. Immediate attention to patching and securing file upload features is advised to mitigate risks.