3.5
CVSSv2

CVE-2020-5298

Published: 03/06/2020 Updated: 30/06/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In OctoberCMS (october/october composer package) versions from 1.0.319 and prior to 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be socially engineered by an malicious user to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in question Issue has been patched in Build 466 (v1.0.466).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

octobercms october

Exploits

October CMS builds 465 and below suffer from arbitrary file read, arbitrary file deletion, file uploading to arbitrary locations, persistent and reflective cross site scripting, and CSV injection vulnerabilities ...