October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool. This issue has been patched in version 3.5.15.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-26T15:55:35.578Z
Updated: 2024-08-01T23:44:09.889Z
Reserved: 2024-02-08T22:26:33.513Z
Link: CVE-2024-25637

Updated: 2024-08-01T23:44:09.889Z

Status : Awaiting Analysis
Published: 2024-06-26T16:15:10.910
Modified: 2024-11-21T09:01:07.820
Link: CVE-2024-25637

No data.