CVE-2020-5298

CVE-2020-5298

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be socially engineered by an attacker to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in question Issue has been patched in Build 466 (v1.0.466).

Source: CVE-2020-5298

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다