CVE-2017-1000119

HIGH7.2EPSS 76.2%

October CMS PHP Code Execution

Published: 5/13/2022Modified: 2/16/2024

Description

October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (4)