CVE-2017-1000196
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-c328b7b99eac0d17b3c71eb37038fd61R49
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| octobercms | october | {"endIncluding":"1.0.412"} | |
References
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.