{"id":"CVE-2024-24764","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-24764","summary":"October System module has an Open Redirect for Administrator Accounts","details":"### Impact\n\nThis advisory affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema.  The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect outside the scope of the active host.\n\nThis vulnerability assumes a trusted user will attack another trusted user and cannot be actively exploited without access to the administration panel and interaction from the other user.\n\n### Patches\n\nThis issue has been patched in v3.5.15.\n\n### References\n\nCredits to:\n- [Benzetaa](https://github.com/benzetaa/)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [hello@octobercms.com](mailto:hello@octobercms.com)","published":"2024-06-26T17:42:18Z","modified":"2024-06-26T17:59:59.662405Z","cvss":{"score":3.5,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:L"},"epss":{"score":0.00265,"percentile":0.1817,"asOf":"2026-08-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"october/system","fixedVersion":"3.5.15"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/octobercms/october/security/advisories/GHSA-v2vf-jv88-3fp5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24764"},{"type":"PACKAGE","url":"https://github.com/octobercms/october"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-06-26T17:59:59.662405Z"}}