← Back

CVE-2017-1000195

nvd nist
Published: Nov 17, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.

Affected (1)

Products: Octobercms: October
1 product
October
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.412

Timeline

No history available yet.