Description
October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to `cms.safe_mode` being enabled can write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This issue has been patched in 3.4.15.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3005 | October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to `cms.safe_mode` being enabled can write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This issue has been patched in 3.4.15. |
Github GHSA |
GHSA-p8q3-h652-65vx | October CMS safe mode bypass using Twig sandbox escape |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T20:07:33.274Z
Reserved: 2023-09-28T17:56:32.612Z
Link: CVE-2023-44382
No data.
Status : Modified
Published: 2023-12-01T22:15:09.780
Modified: 2024-11-21T08:25:47.100
Link: CVE-2023-44382
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA