PT-2020-14312 · October · October Cms

Ka1N4T

·

Published

2020-11-23

·

Updated

2021-11-18

·

CVE-2020-15247

CVSS v3.1

5.2

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions October CMS versions 1.0.319 through 1.0.468
Description The issue allows an authenticated backend user with the cms.manage pages, cms.manage layouts, or cms.manage partials permissions to write specific Twig code to escape the Twig sandbox and execute arbitrary PHP, despite cms.enableSafeMode being enabled. This is a problem for anyone relying on cms.enableSafeMode to ensure that users with those permissions in production do not have access to write and execute arbitrary PHP.
Recommendations For October CMS versions 1.0.319 through 1.0.468, update to Build 469 (v1.0.469) or v1.1.0 to resolve the issue. As a temporary workaround, consider applying the patch manually by using the comparison provided at https://github.com/octobercms/october/compare/106daa2930de4cebb18732732d47d4056f01dd5b...7cb148c1677373ac30ccfd3069d18098e403e1ca to your installation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15247
GHSA-94VP-RMQV-5875

Affected Products

October Cms