October CMS build 412 is vulnerable to PHP object...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Nov 17, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.
References