icon

We found results for “

CVE-2018-1999009

Good to know:

icon

Date: July 23, 2018

October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Exposure of Sensitive Information to an Unauthorized Actor

CWE-200

Top Fix

icon

Upgrade Version

Upgrade to version multisolution/october - v1.0.352;multisolution/october - v1.0.320;multisolution/october - v1.0.355;multisolution/october - v1.0.358;multisolution/october - dev-layout-experiment;multisolution/october - no_fix;multisolution/october - v1.0.343;october/system - v1.0.366;october/system - v1.0.386;october/system - v1.0.320;october/system - v1.0.358;october/system - v1.0.375;october/system - v1.0.391;october/system - v1.0.395;october/system - v1.0.343;october/system - v1.0.355;october/system - v1.0.326;october/system - v1.0.411;october/system - v1.0.421;october/system - v1.0.352;october/system - v1.0.362;october/system - v1.0.437;october/system - v1.0.383;october/system - v1.0.378;october/cms - v1.0.330;october/cms - v1.0.366;october/cms - v1.0.437;october/cms - v1.0.382;october/cms - v1.0.320;october/cms - v1.0.323;october/cms - v1.0.429;october/cms - v1.0.362;october/cms - v1.0.424;october/cms - v1.0.343;october/cms - v1.0.364;october/cms - v1.0.411;october/cms - v1.0.352;october/cms - v1.0.378;october/cms - v1.0.408;october/cms - v1.0.395;october/cms - v1.0.421;october/cms - v1.0.326;october/cms - v1.0.370;october/cms - v1.0.389;october/cms - v1.0.400;october/cms - v1.0.358;october/cms - v1.0.355;october/cms - v1.0.340;october/cms - v1.0.328;october/cms - v1.0.372;october/cms - v1.0.336;october/backend - v1.0.417;october/backend - v1.0.421;october/backend - v1.0.424;october/backend - v1.0.343;october/backend - v1.0.429;october/backend - v1.0.352;october/backend - v1.0.362;october/backend - v1.0.387;october/backend - v1.0.414;october/backend - v1.0.438;october/backend - v1.0.355;october/backend - v1.0.400;october/backend - v1.0.358;october/backend - v1.0.320;october/backend - v1.0.336;october/backend - v1.0.408;cludy-me/octobercms - v1.0.438;klaasie/system - v1.0.437;wintercms/winter - v1.0.438;klaasie/backend - v1.0.438;october/october - v1.0.438;crocwork/cms - v1.0.438;klaasie/cms - v1.0.437

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): PARTIAL
Integrity (I): PARTIAL
Availability (A): PARTIAL
Additional information:

Do you need more information?

Contact Us