CVE-2024-45962: October CMS October

Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.

October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.

Affected products

Published 2024-10-02. Last modified 2026-06-17.