CVE-2020-15128
- EPSS 0.11%
- Veröffentlicht 31.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:04:54
In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabilities in user facing code (noth...
CVE-2020-11083
- EPSS 0.92%
- Veröffentlicht 14.07.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:56:45
In October from version 1.0.319 and before version 1.0.466, a user with access to a markdown FormWidget that stores data persistently could create a stored XSS attack against themselves and any other users with access to the generated HTML from the f...
CVE-2020-4061
- EPSS 0.31%
- Veröffentlicht 02.07.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:14
In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froala richeditor could result in a successful self-XSS attack. This has been fixed in 1.0.467.
CVE-2020-5299
- EPSS 0.67%
- Veröffentlicht 03.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:51
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually be exported as a CSV file from the `ImportExportController` could potentially introduce a C...
CVE-2020-5298
- EPSS 0.76%
- Veröffentlicht 03.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:51
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be socially engineered by an attacker to upload a maliciou...
- EPSS 1.76%
- Veröffentlicht 03.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:51
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to upload jpg, jpeg, bmp, png, webp, gif, ico, css, js, woff, woff2, svg, ttf, eot, json, md, less, sass, scss, xml ...
CVE-2020-5296
- EPSS 0.62%
- Veröffentlicht 03.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:51
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October CMS server. The vulnerability is only exploitable by an authenticated ...
CVE-2020-5295
- EPSS 9.68%
- Veröffentlicht 03.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:51
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user...
CVE-2018-1999009
- EPSS 1.8%
- Veröffentlicht 23.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:02
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack app...
CVE-2018-1999008
- EPSS 0.33%
- Veröffentlicht 23.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:02
October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in the Media module and create folder functionality that can result in an Authenticated user with media module permission creating arbitrary folder name with X...