CVE-2017-1000119
October CMS PHP Code Execution
7.2
HIGH
CVSS 3.1
EPSS 61.3%
Description
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.
How to fix CVE-2017-1000119
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Packagist/october/cms—no fix listed
Is CVE-2017-1000119 being exploited?
Likely — EPSS is 61.3%, placing CVE-2017-1000119 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, <= 1.0.412
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.2 | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |