ZeroHour

CVE-2020-15248

CVSS 3.1
4.2 medium
EPSS
<1%p24
Published
()
Modified
Description

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have access to create & manage users where they can choose which role the new user has. This means that a user with "Publisher" access has the ability to escalate their access to "Developer" access. Issue has been patched in Build 470 (v1.0.470) & v1.1.1.

Vendors
octobercms
Products
october
Weakness
CWE-863, CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.