ZeroHour

CVE-2017-1000195

CVSS 3.0
7.5 high
EPSS
2%p73
Published
()
Modified
Description

October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.

Vendors
octobercms
Products
october
Weakness
CWE-502
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.