CVE-2017-1000197
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-eef90a4e3585febf6489916dc242d0ceR241
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| octobercms | october | {"endIncluding":"1.0.412"} | |
References
CWEs
CWE-417
Verify integrity in audit chain (admin only). AS-IS.