LiveActive security incident?Get immediate response
CVE Record

CVE-2018-1999008: October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in the Media mod...

October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in the Media module and create folder functionality that can result in an Authenticated user with media module permission creating arbitrary folder name with XSS content. This attack appear to be exploitable via an Authenticated user with media module permission who can create arbitrary folder name (XSS). This vulnerability appears to have been fixed in build 437.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2018-1999008 is an authenticated cross-site scripting issue in October CMS before build 437. A user with Media module permission could create a folder name containing script content. The vendor release notes indicate it was fixed in build 437. Business urgency depends on whether untrusted or lower-privileged users can access the Media module.

Executive priority

Prioritize remediation if October CMS is used with multiple content editors or delegated media access. For single-admin, tightly controlled systems, urgency is lower but upgrade should still be scheduled because the vendor identified a fixed build.

Technical view

October CMS prior to build 437 allowed XSS through arbitrary folder names in the Media module create-folder function. Exploitation requires an authenticated user with Media module permission. Public source data does not provide CVSS, CWE, or detailed affected package metadata. The stated fix is October CMS build 437.

Likely exposure

Exposure is most likely on October CMS installations running builds before 437 where non-administrator or semi-trusted users have Media module permissions. Internet exposure matters less than authenticated backend access, but compromise of CMS users could increase impact.

Exploitation context

No CISA KEV listing or provided source reports active exploitation. The issue is not described as unauthenticated or remote without credentials. Impact is typical stored XSS risk: malicious script execution in another user’s browser within the CMS context.

Researcher notes

The public record is sparse: no CVSS vector, CWE, PoC status, or expanded version matrix is provided. Analysis should stay anchored to October CMS before build 437 and the Media module create-folder XSS described in the CVE and vendor reference.

Mitigation direction

  • Upgrade October CMS to build 437 or later, per vendor release notes.
  • Restrict Media module permissions to trusted users only.
  • Review vendor guidance for any additional hardening or upgrade notes.
  • Remove or rename suspicious media folders containing script-like content.

Validation and detection

  • Confirm the October CMS build number is 437 or later.
  • Inventory users and roles with Media module permission.
  • Review media folder names for suspicious markup or script content.
  • Check CMS logs for unusual folder creation by authenticated users.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-1999008 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.