Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xwjr-6fj7-fc6h

Опубликовано: 23 нояб. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Local File Inclusion by unauthenticated users

Impact

An attacker can exploit this vulnerability to read local files on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request.

Patches

Issue has been patched in Build 469 (v1.0.469) and v1.1.0.

Workarounds

Apply https://github.com/octobercms/library/commit/80aab47f044a2660aa352450f55137598f362aa4 to your installation manually if unable to upgrade to Build 469.

References

Reported by ka1n4t

For more information

If you have any questions or comments about this advisory:

Threat assessment:

Screen Shot 2020-10-10 at 1 05 19 PM

Пакеты

Наименование

october/cms

composer
Затронутые версииВерсия исправления

>= 1.0.421, < 1.0.469

1.0.469

EPSS

Процентиль: 77%
0.01094
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-863

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1.0.469, an attacker can read local files on an October CMS server via a specially crafted request. Issue has been patched in Build 469 (v1.0.469) and v1.1.0.

EPSS

Процентиль: 77%
0.01094
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-863