Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-15249— Stored XSS by authenticated backend user with access to upload files

CVSS 2.8 · Low EPSS 0.17% · P37
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-15249

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stored XSS by authenticated backend user with access to upload files
Source: NVD (National Vulnerability Database)
Vulnerability Description
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.469, backend users with access to upload files were permitted to upload SVG files without any sanitization applied to the uploaded files. Since SVG files support being parsed as HTML by browsers, this means that they could theoretically upload Javascript that would be executed on a path under the website's domain (i.e. /storage/app/media/evil.svg), but they would have to convince their target to visit that location directly in the target's browser as the backend does not display SVGs inline anywhere, SVGs are only displayed as image resources in the backend and are thus unable to be executed. Issue has been patched in Build 469 (v1.0.469) & v1.1.0.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: NVD (National Vulnerability Database)
Vulnerability Title
October CMS 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
October CMS是一套基于PHP和Laravel Web应用程序框架的开源内容管理系统(CMS)。 October CMS 1.0.319版本和1.0.469版本存在安全漏洞,该漏洞允许具有上传文件权限的后端用户上传SVG文件,而无需对上传的文件进行任何处理。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
octobercmsoctober >= 1.0.319, < 1.0.469 -

II. Public POCs for CVE-2020-15249

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-15249

登录查看更多情报信息。

Same Patch Batch · octobercms · 2020-11-23 · 5 CVEs total

CVE-2020-152467.5 HIGHLocal File Inclusion by unauthenticated users
CVE-2020-152475.2 MEDIUMTwig Sandbox Escape by authenticated users with access to editing CMS templates when safem
CVE-2020-262315.2 MEDIUMBypass of fix for CVE-2020-15247, Twig sandbox escape
CVE-2020-152484.0 MEDIUMPrivilege escalation by backend users assigned to the default "Publisher" system role

IV. Related Vulnerabilities

V. Comments for CVE-2020-15249

No comments yet


Leave a comment