PT-2022-3951 · Unknown · October Cms

Published

2022-03-29

·

Updated

2022-07-20

·

CVE-2022-24800

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions October CMS versions prior to 1.0.476 October CMS versions prior to 1.1.12 October CMS versions prior to 2.2.15
Description The issue is related to the implementation of the fromData method in the October CMS system, which allows for remote code execution (RCE) by exploiting a race condition in the temporary storage directory. This can be done by an unauthenticated user when the developer allows the user to specify their own filename in the fromData method. The vulnerability affects plugins that expose the OctoberRainDatabaseAttachFile::fromData as a public interface, but does not affect vanilla installations of October CMS.
Recommendations For versions prior to 1.0.476, update to Build 476 (v1.0.476) or apply the patch manually as a workaround. For versions prior to 1.1.12, update to v1.1.12 or apply the patch manually as a workaround. For versions prior to 2.2.15, update to v2.2.15 or apply the patch manually as a workaround. As a temporary workaround, consider restricting access to the OctoberRainDatabaseAttachFile::fromData method to minimize the risk of exploitation.

Exploit

Fix

RCE

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04781
CVE-2022-24800
GHSA-8V7H-CPC2-R8JP

Affected Products

October Cms