CVE Vulnerabilities

CVE-2017-1000197

Published: Nov 17, 2017 | Modified: Aug 03, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.

Affected Software

Name Vendor Start Version End Version
October Octobercms * 1.0.412 (including)

References