{"id":"GHSA-9hq8-v2jc-qj4r","summary":"October CMS XSS In Caption Tag of Profile","details":"Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via the caption tag of a profile image.","aliases":["CVE-2015-5612"],"modified":"2023-11-08T03:57:58.473713Z","published":"2022-05-17T04:08:19Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-08-04T23:08:04Z","nvd_published_at":"2015-09-04T15:59:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-5612"},{"type":"WEB","url":"https://github.com/octobercms/october/issues/1302"},{"type":"WEB","url":"https://github.com/octobercms/october/commit/8a4ac533e5cd6b8f92e9ef19fbfbb2f505dc7a9a"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/07/21/5"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/07/22/3"}],"affected":[{"package":{"name":"october/october","ecosystem":"Packagist","purl":"pkg:composer/october/october"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.319"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9hq8-v2jc-qj4r/GHSA-9hq8-v2jc-qj4r.json"}}],"schema_version":"1.9.0"}