VYPR
Medium severity6.1NVD Advisory· Published Nov 17, 2017· Updated May 13, 2026

CVE-2017-1000193

CVE-2017-1000193

Description

October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
october/octoberPackagist
< 1.0.4131.0.413

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.