ZeroHour

CVE-2017-1000193

CVSS 3.0
6.1 medium
EPSS
1%p61
Published
()
Modified
Description

October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.

Vendors
octobercms
Products
october
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.