Cross Site Scripting Vulnerability Allows Local Attacker to Execute Arbitrary Code
CVE-2023-25365

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
8 February 2024

What is CVE-2023-25365?

A cross site scripting vulnerability exists in October CMS version 3.2.0 that poses significant security risks. This vulnerability allows local attackers to execute arbitrary code through a specific file type (.mp3) via a file upload mechanism. Users of affected versions should be aware of the potential for unauthorized access and the exploitation of this security flaw, which may lead to further complications within the web application environment. Immediate attention to patching and securing file upload features is advised to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.