CVE-2017-1000193: XSS
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.
Other sources
October CMS build 412 is vulnerable to stored XSS in brand logo image name resulting in JavaScript code execution in the victim's browser.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-1000193?
CVE-2017-1000193 is a vulnerability in October CMS build 412 that allows for stored Cross-Site Scripting (XSS) attacks through the brand logo image name, resulting in the execution of JavaScript code in the victim's browser.
How severe is CVE-2017-1000193?
CVE-2017-1000193 has a severity level of medium with a CVSS score of 6.1.
What software versions are affected by CVE-2017-1000193?
October CMS versions up to and including 1.0.412 are affected by CVE-2017-1000193.
How can I fix CVE-2017-1000193?
To fix CVE-2017-1000193, it is recommended to update October CMS to version 1.0.413 or higher.
What is the Common Weakness Enumeration (CWE) for CVE-2017-1000193?
The CWE for CVE-2017-1000193 is CWE-79, which relates to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').