ZeroHour

CVE-2017-1000194

CVSS 3.0
9.8 critical
EPSS
1%p67
Published
()
Modified
Description

October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.

Vendors
octobercms
Products
october
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.