CVE-2024-45962: October CMS October
Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.
Affected products
- October CMS October: version 3.6.30 only
Published 2024-10-02. Last modified 2026-06-17.