High severityNVD Advisory· Published Nov 23, 2020· Updated Aug 4, 2024
Local File Inclusion by unauthenticated users
CVE-2020-15246
Description
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1.0.469, an attacker can read local files on an October CMS server via a specially crafted request. Issue has been patched in Build 469 (v1.0.469) and v1.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
october/cmsPackagist | >= 1.0.421, < 1.0.469 | 1.0.469 |
Affected products
2- Range: >= 1.0.421, < 1.0.469
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-xwjr-6fj7-fc6hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-15246ghsaADVISORY
- github.com/octobercms/library/commit/80aab47f044a2660aa352450f55137598f362aa4ghsax_refsource_MISCWEB
- github.com/octobercms/october/security/advisories/GHSA-xwjr-6fj7-fc6hghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.