Unauthorized File Upload Vulnerability in October CMS by October
CVE-2024-51991

1.1LOW

Key Information:

Vendor

Octobercms

Status
Vendor
CVE Published:
5 May 2025

What is CVE-2024-51991?

A security issue in October CMS versions prior to 3.7.5 allows authenticated administrators to bypass the media sanitization process for SVG files. This vulnerability arises when users exploit the media.clean_vectors configuration by initially uploading an SVG file using a permitted extension like .jpg or .png, and then renaming it to .svg. This exploit necessitates administrative panel access and relies on trust between users, making it critical for administrators to ensure that their versions are updated to prevent potential exploitation.

Affected Version(s)

october < 3.7.5

References

CVSS V4

Score:
1.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.