Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
October CMS 安全漏洞
Vulnerability Description
October CMS是October CMS公司的一套基于PHP和Laravel Web应用程序框架的开源内容管理系统(CMS)。 October CMS 3.6.30版本存在安全漏洞。攻击者利用该漏洞执行跨站点脚本攻击或通过特制的JavaScript对目标执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A