Vulnerability CVE-2020-5295


Published: 2020-06-03   Modified: 2020-06-04

Description:
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).

Type:

CWE-98

(Improper Control of Filename for Include/Require Statement in PHP Program ('PHP File Inclusion'))

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Octobercms -> October 

 References:
https://github.com/octobercms/october/commit/2b8939cc8b5b6fe81e093fe2c9f883ada4e3c8cc
https://github.com/octobercms/october/security/advisories/GHSA-r23f-c2j5-rx2f

Copyright 2024, cxsecurity.com

 

Back to Top