October · October Cms · CVE-2020-15248
**Name of the Vulnerable Software and Affected Versions**
October CMS versions 1.0.319 through 1.0.470
**Description**
October CMS is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In affected versions, backend users with the default "Publisher" system role have access to create and manage users, allowing them to choose which role the new user has. This means that a user with "Publisher" access has the ability to escalate their access to "Developer" access.
**Recommendations**
For versions 1.0.319 through 1.0.470, update to Build 470 (v1.0.470) or v1.1.1 to resolve the issue.
As a temporary workaround for versions that cannot be updated to Build 470 or v1.1.1, apply the manual patch from https://github.com/octobercms/october/commit/78a37298a4ed4602b383522344a31e311402d829 to your installation.