CVE-2023-37692: XSS
An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file.
Other sources
An svg file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code in the context of a browser via a crafted svg file. Attackers must be authenticated as users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37692?
The severity of CVE-2023-37692 is medium (5.4).
How does the arbitrary file upload vulnerability in October CMS v3.4.4 work?
The vulnerability allows attackers to upload and execute arbitrary code using a crafted svg file.
Who is affected by CVE-2023-37692?
Users of October CMS v3.4.4 are affected by CVE-2023-37692.
How can I mitigate CVE-2023-37692?
To mitigate CVE-2023-37692, update to a version of October CMS that is not affected by the vulnerability.
Where can I find more information about CVE-2023-37692?
You can find more information about CVE-2023-37692 on the NIST National Vulnerability Database, as well as through the provided references.