CVE-2024-24764

LOW

October CMS <3.5.15 - Open Redirect

Title source: llm
STIX 2.1

Description

October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect outside the scope of the active host. This vulnerability has been patched in version 3.5.15.

References (1)

Core 1
Core References

Scores

CVSS v3 3.5
EPSS 0.0027
EPSS Percentile 17.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
october/system 3.2 - 3.5.15Packagist
octobercms/october 3.2.0 - 3.5.15
Published Jun 26, 2024
Tracked Since Feb 18, 2026