CVE-2024-24764: October System module has an Open Redirect for Administrator Accounts
3.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.26029%
CWE
Published
6/26/2024
Updated
6/26/2024
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:L
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| october/system | composer | >= 3.2, < 3.5.15 | 3.5.15 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability centers on improper handling of 'october://' URIs in the PageFinder component. The advisory explicitly states the resolver allowed external links, which indicates the URI resolution function lacked proper validation. The PageFinder class is logically responsible for link resolution in the system module, and its resolve method would be the primary entry point for processing these schema-based links. The high confidence comes from the direct correlation between the described vulnerability pattern (open redirect via custom URI scheme) and typical implementation patterns in CMS architectures.