High severity7.5NVD Advisory· Published Nov 23, 2020· Updated Jun 17, 2026
CVE-2020-15246
CVE-2020-15246
Description
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1.0.469, an attacker can read local files on an October CMS server via a specially crafted request. Issue has been patched in Build 469 (v1.0.469) and v1.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
october/cmsPackagist | >= 1.0.421, < 1.0.469 | 1.0.469 |
Affected products
3cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*range: >=1.0.421,<1.0.469
- (no CPE)range: >= 1.0.421, < 1.0.469
Patches
Vulnerability mechanics
References
4- github.com/octobercms/library/commit/80aab47f044a2660aa352450f55137598f362aa4nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-xwjr-6fj7-fc6hghsaADVISORY
- github.com/octobercms/october/security/advisories/GHSA-xwjr-6fj7-fc6hnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15246ghsaADVISORY
News mentions
0No linked articles in our index yet.