October CMS Build 465 XSS / File Read / File Deletion / CSV Injection

October CMS builds 465 and below suffer from arbitrary file read, arbitrary file deletion, file uploading to arbitrary locations, persistent and reflective cross site scripting, and CSV injection vulnerabilities.

Leave a Reply