CVE-2017-1000195

HIGH

October CMS <build 412 - Code Injection

Title source: llm
STIX 2.1

Description

October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.

Scores

CVSS v3 7.5
EPSS 0.0152
EPSS Percentile 71.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-502
Status published
Products (1)
octobercms/october < 1.0.412
Published Nov 17, 2017
Tracked Since Feb 18, 2026