PT-2020-14311 · October · October Cms

Ka1N4T

·

Published

2020-11-23

·

Updated

2021-11-18

·

CVE-2020-15246

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions October CMS versions 1.0.421 through 1.0.468
Description An attacker can exploit this issue to read local files on an October CMS server via a specially crafted request. The issue is exploitable by unauthenticated users.
Recommendations For versions 1.0.421 through 1.0.468, update to Build 469 (v1.0.469) or v1.1.0 to resolve the issue. As a temporary workaround for versions that cannot be updated to Build 469, apply the patch from https://github.com/octobercms/library/commit/80aab47f044a2660aa352450f55137598f362aa4 to your installation manually.

Fix

Incorrect Authorization

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15246
GHSA-XWJR-6FJ7-FC6H

Affected Products

October Cms