CVE-2017-1000193

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/11/2017
Last modified:
20/04/2025

Description

October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* 1.0.412 (including)