Описание
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:octobercms:october:-:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.01893
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
EPSS
Процентиль: 83%
0.01893
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-200