SB2017100521 - Arbitrary file upload in OctoberCMS October CMS



SB2017100521 - Arbitrary file upload in OctoberCMS October CMS

Published: October 5, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017100521
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Arbitrary file upload (CVE-ID: CVE-2017-1000119)

The vulnerability allows a remote privileged user to execute arbitrary code.

October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.


Remediation

Install update from vendor's website.