CVE-2015-5612 describes a cross-site scripting (XSS) vulnerability in October CMS, specifically in build 271 and earlier versions. This flaw allows unauthenticated remote attackers to inject arbitrary web script or HTML by manipulating the caption tag of a profile image. While the CVSS score is 4.3 (medium severity) with a low impact on integrity, it has a low EPSS score and FAUCET risk score, indicating a low likelihood of exploitation. There is no known exploit code available (Metasploit, Nuclei, ExploitDB), and it shows no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:octobercms:october:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.