CVE Vulnerabilities

CVE-2017-1000197

Published: Nov 17, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.

Affected Software

NameVendorStart VersionEnd Version
OctoberOctobercms*1.0.412 (including)

References