Description
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5309 | October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437. |
Github GHSA |
GHSA-v7cr-w5v6-6659 | October CMS Local File Inclusion |
References
| Link | Providers |
|---|---|
| http://octobercms.com/support/article/rn-10 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T00:06:26.182Z
Reserved: 2018-07-23T00:00:00.000Z
Link: CVE-2018-1999009
No data.
Status : Modified
Published: 2018-07-23T15:29:00.253
Modified: 2024-11-21T03:57:02.443
Link: CVE-2018-1999009
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA