CVE-2017-1000119
HIGH7.2EPSS 76.2%October CMS PHP Code Execution
Published: 5/13/2022Modified: 2/16/2024
Description
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.
Affected packages (1)
- Packagist/october/cmsfrom 0, <= 1.0.412
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.2 | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |