CVE-2020-5298: Reflected XSS when importing CSV in OctoberCMS

Published Jun 3, 2020
·
Updated

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the ImportExportController behavior can be socially engineered by an attacker to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in question Issue has been patched in Build 466 (v1.0.466).

Affected Software

1 affected component
October CMS Debugbar>=1.0.319<1.0.466

Event History

Jun 3, 2020
CVE Published
via MITRE·09:55 PM
Data Sourced
via MITRE·09:55 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2020-5298?

CVE-2020-5298 is a vulnerability in OctoberCMS versions from 1.0.319 and before 1.0.466 that allows a socially engineered attacker to upload a malicious CSV file through the import functionality of the ImportExportController behavior, potentially leading to a reflected Cross-Site Scripting (XSS) attack.

2

What is the severity of CVE-2020-5298?

CVE-2020-5298 has a severity rating of 4.8, which is considered medium.

3

How can the CVE-2020-5298 vulnerability be exploited?

The CVE-2020-5298 vulnerability can be exploited by tricking a user with import functionality access to upload a specially crafted CSV file containing malicious code.

4

What is the affected software for CVE-2020-5298?

The affected software for CVE-2020-5298 is OctoberCMS versions from 1.0.319 and before 1.0.466.

5

Is there a fix available for CVE-2020-5298?

Yes, a fix is available for CVE-2020-5298. It is recommended to update OctoberCMS to version 1.0.466 or newer to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203