vendor:
OctoberCMS
by:
Sivanesh Ashok
4.9
CVSS
MEDIUM
Arbitrary File Read
22
CWE
Product Name: OctoberCMS
Affected Version From: Build 465
Affected Version To: Build 465
Patch Exists: YES
Related CWE: CVE-2020-5295
CPE: a:octobercms:octobercms:1.0.45
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 / XAMPP / October CMS Build 465
2020
October CMS Build 465 – Arbitrary File Read Exploit (Authenticated)
This exploit allows an authenticated user to read arbitrary files from the October CMS <= Build 465. The exploit requires the user to have the privilege to modify assets and a valid cookie value. The relative path to the target file is required to exploit the vulnerability.
Mitigation:
Upgrade to the latest version of October CMS.