CVE-2020-5296
Summary
| CVE | CVE-2020-5296 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-03 22:15:00 UTC |
| Updated | 2022-06-30 14:46:00 UTC |
| Description | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466). |
Risk And Classification
Problem Types: CWE-610
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Octobercms | October | All | All | All | All |
| Application | Octobercms | October | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| October CMS Build 465 XSS / File Read / File Deletion / CSV Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Improve asset file path handling · octobercms/october@2b8939c · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Arbitrary File Deletion by authenticated backend user with cms.manage_assets permission · Advisory · octobercms/october · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Full Disclosure: October CMS <= Build 465 Multiple Vulnerabilities - Arbitrary File Read | FULLDISC | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.