CVE-2020-5298: Reflected XSS when importing CSV in OctoberCMS
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the ImportExportController behavior can be socially engineered by an attacker to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in question Issue has been patched in Build 466 (v1.0.466).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-5298?
CVE-2020-5298 is a vulnerability in OctoberCMS versions from 1.0.319 and before 1.0.466 that allows a socially engineered attacker to upload a malicious CSV file through the import functionality of the ImportExportController behavior, potentially leading to a reflected Cross-Site Scripting (XSS) attack.
What is the severity of CVE-2020-5298?
CVE-2020-5298 has a severity rating of 4.8, which is considered medium.
How can the CVE-2020-5298 vulnerability be exploited?
The CVE-2020-5298 vulnerability can be exploited by tricking a user with import functionality access to upload a specially crafted CSV file containing malicious code.
What is the affected software for CVE-2020-5298?
The affected software for CVE-2020-5298 is OctoberCMS versions from 1.0.319 and before 1.0.466.
Is there a fix available for CVE-2020-5298?
Yes, a fix is available for CVE-2020-5298. It is recommended to update OctoberCMS to version 1.0.466 or newer to mitigate the vulnerability.