High severity7.5NVD Advisory· Published Nov 17, 2017· Updated May 13, 2026
CVE-2017-1000195
CVE-2017-1000195
Description
October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.