PT-2020-14312 · October · October Cms
Ka1N4T
·
Published
2020-11-23
·
Updated
2021-11-18
·
CVE-2020-15247
CVSS v3.1
5.2
Medium
| Vector | AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
October CMS versions 1.0.319 through 1.0.468
Description
The issue allows an authenticated backend user with the
cms.manage pages, cms.manage layouts, or cms.manage partials permissions to write specific Twig code to escape the Twig sandbox and execute arbitrary PHP, despite cms.enableSafeMode being enabled. This is a problem for anyone relying on cms.enableSafeMode to ensure that users with those permissions in production do not have access to write and execute arbitrary PHP.Recommendations
For October CMS versions 1.0.319 through 1.0.468, update to Build 469 (v1.0.469) or v1.1.0 to resolve the issue.
As a temporary workaround, consider applying the patch manually by using the comparison provided at https://github.com/octobercms/october/compare/106daa2930de4cebb18732732d47d4056f01dd5b...7cb148c1677373ac30ccfd3069d18098e403e1ca to your installation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
October Cms