Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-35944

Опубликовано: 13 окт. 2022
Источник: nvd
CVSS3: 6.2
CVSS3: 7.2
EPSS Низкий

Описание

October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing public access to the admin panel. Assuming an attacker has access to the admin panel and permission to open the "Editor" section, they can bypass the Safe Mode (cms.safe_mode) restriction to introduce new PHP code in a CMS template using a specially crafted request. The issue has been patched in versions 2.2.34 and 3.0.66.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*
Версия до 2.2.34 (исключая)
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*
Версия от 3.0.00 (включая) до 3.0.66 (исключая)

EPSS

Процентиль: 66%
0.00504
Низкий

6.2 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

October CMS Safe Mode bypass leads to authenticated Remote Code Execution

EPSS

Процентиль: 66%
0.00504
Низкий

6.2 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-94