CVE-2018-1999009

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
23/07/2018
Last modified:
03/08/2020

Description

October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octobercms:october:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools