| |
Vulnerability CVE-2020-15246
Published: 2020-11-23
Description: |
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1.0.469, an attacker can read local files on an October CMS server via a specially crafted request. Issue has been patched in Build 469 (v1.0.469) and v1.1.0. |
Type:
CWE-863 (Incorrect Authorization)
CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5/10 |
2.9/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://github.com/octobercms/library/commit/80aab47f044a2660aa352450f55137598f362aa4
https://github.com/octobercms/october/security/advisories/GHSA-xwjr-6fj7-fc6h
|
|
|
Copyright 2024, cxsecurity.com
|
|
|