icon

We found results for “

CVE-2023-44382

Date: December 1, 2023

October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the "editor.cms_pages", "editor.cms_layouts", or "editor.cms_partials" permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to "cms.safe_mode" being enabled can write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This issue has been patched in 3.4.15.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Control of Generation of Code ('Code Injection')

CWE-94

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us