Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v7cr-w5v6-6659

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

October CMS Local File Inclusion

October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.

Пакеты

Наименование

october/october

composer
Затронутые версииВерсия исправления

< 1.0.437

1.0.437

EPSS

Процентиль: 82%
0.01798
Низкий

8.1 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8.1
nvd
больше 7 лет назад

October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.

EPSS

Процентиль: 82%
0.01798
Низкий

8.1 High

CVSS3

Дефекты

CWE-200