Unauthorized File Upload Vulnerability in October CMS by October
CVE-2024-51991
1.1LOW
What is CVE-2024-51991?
A security issue in October CMS versions prior to 3.7.5 allows authenticated administrators to bypass the media sanitization process for SVG files. This vulnerability arises when users exploit the media.clean_vectors configuration by initially uploading an SVG file using a permitted extension like .jpg or .png, and then renaming it to .svg. This exploit necessitates administrative panel access and relies on trust between users, making it critical for administrators to ensure that their versions are updated to prevent potential exploitation.
Affected Version(s)
october < 3.7.5
