We found results for “”
CVE-2023-44381
Date: December 1, 2023
October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the "editor.cms_pages", "editor.cms_layouts", or "editor.cms_partials" permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to "cms.safe_mode" being enabled can craft a special request to include PHP code in the CMS template. This issue has been patched in version 3.4.15.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Control of Generation of Code ('Code Injection')
CWE-94CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


