CVE detail
CVE-2020-5298 — CVE-2020-5298
Published 2020-06-03 · Modified 2026-06-17 · Vendor octobercms · Product october · Source nvd
MEDIUM
severity
CVSS-derived band
0.0091
EPSS probability
exploitation probability, 30d
57.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be socially engineered by an attacker to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in question Issue has been patched in Build 466 (v1.0.466).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References