CVE-2024-45962: XSS
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45962?
CVE-2024-45962 is considered a high severity vulnerability due to the potential for XSS attacks and arbitrary code execution.
How do I fix CVE-2024-45962?
To mitigate CVE-2024-45962, update October CMS to version 3.6.31 or later, which includes security patches.
Who is affected by CVE-2024-45962?
CVE-2024-45962 affects users of October CMS version 3.6.30 and earlier.
What kind of attack can occur with CVE-2024-45962?
CVE-2024-45962 can lead to Cross-Site Scripting (XSS) attacks and potentially execute arbitrary code when a malicious PDF is accessed.
Can CVE-2024-45962 be exploited by a regular user?
No, CVE-2024-45962 requires an authenticated admin account to upload the malicious file, making it less likely to be exploited by regular users.