ZeroHour

CVE-2017-1000197

CVSS 3.0
9.8 critical
EPSS
1%p67
Published
()
Modified
Description

October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.

Vendors
octobercms
Products
october
Weakness
CWE-417
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.