Octobercms

October

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung
  • EPSS 93.08%
  • Veröffentlicht 26.08.2021 19:15:07
  • Zuletzt bearbeitet 24.10.2025 14:47:44

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has...

  • EPSS 0.5%
  • Veröffentlicht 26.08.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:01:14

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS server. The vul...

  • EPSS 0.03%
  • Veröffentlicht 03.05.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 05:47:53

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 & CVE-2020-15247. An authenticated back...

  • EPSS 0.51%
  • Veröffentlicht 10.03.2021 22:15:12
  • Zuletzt bearbeitet 30.05.2025 00:15:20

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October before version 1.1.2, when running on poorly configured servers (i.e. the server routes any request, regardless of the HOST header to an October C...

Exploit
  • EPSS 1.52%
  • Veröffentlicht 05.02.2021 14:15:19
  • Zuletzt bearbeitet 21.11.2024 06:21:15

An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only...

  • EPSS 0.03%
  • Veröffentlicht 23.11.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:19:36

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-15247 (fixed in 1.0.469 and 1.1.0) was discovered that has the same impact as CVE-2020-15247. An authenticated backend user with the cms...

  • EPSS 0.17%
  • Veröffentlicht 23.11.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:11

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.469, backend users with access to upload files were permitted to upload SVG files without any sani...

  • EPSS 0.05%
  • Veröffentlicht 23.11.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:11

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have access to create & manage users w...

  • EPSS 0.15%
  • Veröffentlicht 23.11.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:10

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.469, an authenticated backend user with the cms.manage_pages, cms.manage_layouts, or cms.manage_pa...

  • EPSS 1.09%
  • Veröffentlicht 23.11.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:10

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1.0.469, an attacker can read local files on an October CMS server via a specially crafted request. Is...