PT-2020-18385 · October · October Cms

Sivanesh Ashok

+1

·

Published

2020-06-03

·

Updated

2022-06-30

·

CVE-2020-5296

CVSS v3.1

6.2

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OctoberCMS versions 1.0.319 through 1.0.465
Description An attacker can exploit this issue to delete arbitrary local files of an October CMS server. The issue is only exploitable by an authenticated backend user with the cms.manage assets permission.
Recommendations For versions 1.0.319 through 1.0.465, update to Build 466 (v1.0.466) to resolve the issue. As a temporary workaround, consider applying the patch from https://github.com/octobercms/october/commit/2b8939cc8b5b6fe81e093fe2c9f883ada4e3c8cc to your installation manually if unable to upgrade to Build 466.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5296
GHSA-JV6V-FVVX-4932

Affected Products

October Cms