PT-2020-14313 · October · October Cms
Hoan Hoang
·
Published
2020-11-23
·
Updated
2021-11-18
·
CVE-2020-15248
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
October CMS versions 1.0.319 through 1.0.470
Description
October CMS is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In affected versions, backend users with the default "Publisher" system role have access to create and manage users, allowing them to choose which role the new user has. This means that a user with "Publisher" access has the ability to escalate their access to "Developer" access.
Recommendations
For versions 1.0.319 through 1.0.470, update to Build 470 (v1.0.470) or v1.1.1 to resolve the issue.
As a temporary workaround for versions that cannot be updated to Build 470 or v1.1.1, apply the manual patch from https://github.com/octobercms/october/commit/78a37298a4ed4602b383522344a31e311402d829 to your installation.
Fix
Incorrect Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
October Cms