CVE-2015-5612: XSS
Published Sep 4, 2015
·Updated
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via the caption tag of a profile image.
Affected Software
2 affected componentsFixes available
composer/october/october<1.0.319
1.0.319
October CMS Debugbar
Remediation
Patch Available
Event History
Sep 4, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 17, 2022
Advisory Published
04:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-5612?
CVE-2015-5612 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-5612?
To fix CVE-2015-5612, upgrade to October CMS version 1.0.319 or later.
3
What types of attacks can CVE-2015-5612 facilitate?
CVE-2015-5612 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary scripts.
4
Which versions of October CMS are affected by CVE-2015-5612?
CVE-2015-5612 affects all October CMS builds prior to version 1.0.319.
5
Can CVE-2015-5612 be exploited remotely?
Yes, CVE-2015-5612 can be exploited remotely by attackers to inject malicious scripts.