Vulnerability Description
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Octobercms | October | >= 1.0.319, < 1.0.466 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/158730/October-CMS-Build-465-XSS-File-Read-ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Aug/2ExploitMailing ListThird Party Advisory
- https://github.com/octobercms/october/commit/2b8939cc8b5b6fe81e093fe2c9f883ada4ePatchThird Party Advisory
- https://github.com/octobercms/october/security/advisories/GHSA-r23f-c2j5-rx2fPatchThird Party Advisory
- http://packetstormsecurity.com/files/158730/October-CMS-Build-465-XSS-File-Read-ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Aug/2ExploitMailing ListThird Party Advisory
- https://github.com/octobercms/october/commit/2b8939cc8b5b6fe81e093fe2c9f883ada4ePatchThird Party Advisory
- https://github.com/octobercms/october/security/advisories/GHSA-r23f-c2j5-rx2fPatchThird Party Advisory
FAQ
What is CVE-2020-5295?
CVE-2020-5295 is a vulnerability with a CVSS score of 4.8 (MEDIUM). In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server. The vulnerability is...
How severe is CVE-2020-5295?
CVE-2020-5295 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5295?
Check the references section above for vendor advisories and patch information. Affected products include: Octobercms October.