Dismissed
(not in Nixpkgs)
Permalink
CVE-2026-27937
3.1 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
October: Reflected XSS via DataTable Form Widget
October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output escaping. This vulnerability is fixed in 3.7.16 and 4.1.16.
References
-
https://github.com/octobercms/october/security/advisories/GHSA-jj38-h5w5-mvpf x_refsource_CONFIRM
Affected products
october
- ==>= 4.0.0, < 4.1.16
- ==< 3.7.16
Matching in nixpkgs
pkgs.typstPackages.october
Simple printable year calendar
pkgs.typstPackages.october_1_0_0
Simple printable year calendar
pkgs.typstPackages.october_1_0_1
Simple printable year calendar
Package maintainers
-
@cherrypiejam Gongqi Huang
-
@RossSmyth Ross Smyth