Описание
October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the editor.cms_pages, editor.cms_layouts, or editor.cms_partials permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to cms.safe_mode being enabled can write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This issue has been patched in 3.4.15.
Уязвимые конфигурации
Конфигурация 1Версия от 3.0.0 (включая) до 3.4.15 (исключая)
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.00246
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 9.1
github
около 2 лет назад
October CMS safe mode bypass using Twig sandbox escape
EPSS
Процентиль: 48%
0.00246
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-94