Reflected XSS when importing CSV in OctoberCMS
Moderate severity
GitHub Reviewed
Published
Jun 2, 2020
in
octobercms/october
•
Updated Jan 27, 2023
Description
Reviewed
Jun 3, 2020
Published to the GitHub Advisory Database
Jun 3, 2020
Published by the National Vulnerability Database
Jun 3, 2020
Last updated
Jan 27, 2023
Impact
A user with the ability to use the import functionality of the
ImportExportController
behavior could be socially engineered by an attacker to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in questionPatches
Issue has been patched in Build 466 (v1.0.466).
Workarounds
Apply octobercms/october@cd0b6a7 to your installation manually if unable to upgrade to Build 466.
References
Reported by Sivanesh Ashok
For more information
If you have any questions or comments about this advisory:
Threat assessment:
### References - https://github.com/octobercms/october/security/advisories/GHSA-gg6x-xx78-448c - https://github.com/octobercms/october/commit/cd0b6a791f995d86071a024464c1702efc50f46c - https://nvd.nist.gov/vuln/detail/CVE-2020-5298 - http://packetstormsecurity.com/files/158730/October-CMS-Build-465-XSS-File-Read-File-Deletion-CSV-Injection.html - http://seclists.org/fulldisclosure/2020/Aug/2