PT-2020-14311 · October · October Cms
Ka1N4T
·
Published
2020-11-23
·
Updated
2021-11-18
·
CVE-2020-15246
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
October CMS versions 1.0.421 through 1.0.468
Description
An attacker can exploit this issue to read local files on an October CMS server via a specially crafted request. The issue is exploitable by unauthenticated users.
Recommendations
For versions 1.0.421 through 1.0.468, update to Build 469 (v1.0.469) or v1.1.0 to resolve the issue.
As a temporary workaround for versions that cannot be updated to Build 469, apply the patch from https://github.com/octobercms/library/commit/80aab47f044a2660aa352450f55137598f362aa4 to your installation manually.
Fix
Incorrect Authorization
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
October Cms