-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability centers on improper handling of 'october://' URIs in the PageFinder component. The advisory explicitly states the resolver allowed external links, which indicates the URI resolution function lacked proper validation. The PageFinder class is logically responsible for link resolution in the system module, and its resolve method would be the primary entry point for processing these schema-based links. The high confidence comes from the direct correlation between the described vulnerability pattern (open redirect via custom URI scheme) and typical implementation patterns in CMS architectures.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| october/system | composer | >= 3.2, < 3.5.15 | 3.5.15 |
Ongoing coverage of React2Shell