CVE-2020-5297
Summary
| CVE | CVE-2020-5297 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-03 22:15:00 UTC |
| Updated | 2022-06-30 14:46:00 UTC |
| Description | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to upload jpg, jpeg, bmp, png, webp, gif, ico, css, js, woff, woff2, svg, ttf, eot, json, md, less, sass, scss, xml files to any directory of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466). |
Risk And Classification
Problem Types: CWE-610
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Octobercms | October | All | All | All | All |
| Application | Octobercms | October | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Improve asset file path handling when moving assets · octobercms/october@6711dae · GitHub | MISC | github.com | Patch, Third Party Advisory |
| October CMS Build 465 XSS / File Read / File Deletion / CSV Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Arbitrary Upload of Whitelisted File Types by authenticated backend user with cms.manage_assets permission · Advisory · octobercms/october · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Full Disclosure: October CMS <= Build 465 Multiple Vulnerabilities - Arbitrary File Read | FULLDISC | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.