CVE-2017-1000194

CRITICAL9.8EPSS 0.41%

October CMS File Upload Vulnerability

Published: 5/13/2022Modified: 2/16/2024
Also known as:GHSA-8vh6-8w76-v6m3

Description

October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (3)