Description
October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to `cms.safe_mode` being enabled can craft a special request to include PHP code in the CMS template. This issue has been patched in version 3.4.15.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3012 | October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to `cms.safe_mode` being enabled can craft a special request to include PHP code in the CMS template. This issue has been patched in version 3.4.15. |
Github GHSA |
GHSA-q22j-5r3g-9hmh | October CMS safe mode bypass using Page template injection |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T20:07:32.781Z
Reserved: 2023-09-28T17:56:32.612Z
Link: CVE-2023-44381
No data.
Status : Modified
Published: 2023-12-01T22:15:09.573
Modified: 2024-11-21T08:25:46.980
Link: CVE-2023-44381
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA