Vulnerability Description
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Octobercms | October | <= 1.0.412 |
Related Weaknesses (CWE)
References
- https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-66d6dfe5ePatch
- https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-66d6dfe5ePatch
FAQ
What is CVE-2017-1000193?
CVE-2017-1000193 is a vulnerability with a CVSS score of 6.1 (MEDIUM). October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.
How severe is CVE-2017-1000193?
CVE-2017-1000193 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000193?
Check the references section above for vendor advisories and patch information. Affected products include: Octobercms October.