Skip to content

Local File Inclusion by unauthenticated users

High
LukeTowers published GHSA-xwjr-6fj7-fc6h Nov 22, 2020

Package

composer october/cms (Composer)

Affected versions

>= 1.0.421, < 1.0.469

Patched versions

1.0.469

Description

Impact

An attacker can exploit this vulnerability to read local files on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request.

Patches

Issue has been patched in Build 469 (v1.0.469) and v1.1.0.

Workarounds

Apply octobercms/library@80aab47 to your installation manually if unable to upgrade to Build 469.

References

Reported by ka1n4t

For more information

If you have any questions or comments about this advisory:

Threat assessment:

Screen Shot 2020-10-10 at 1 05 19 PM

Severity

High

CVE ID

CVE-2020-15246

Weaknesses

No CWEs

Credits