october/system Security Advisories for v1.1.9 (3)
-
[HIGH] October CMS upload process vulnerable to RCE via Race Condition
PKSA-yr75-7y9f-cxw9 CVE-2022-24800 GHSA-8v7h-cpc2-r8jp
Affected version: >=2.0.0,<2.2.15|>=1.1.0,<1.1.12|<1.0.476
Reported by:
GitHub -
[MEDIUM] Missing server signature validation in OctoberCMS
PKSA-9y13-4h42-rz75 CVE-2022-23655 GHSA-53m6-44rc-h2q5
Affected version: <1.0.475|>=1.1.0,<1.1.11
Reported by:
GitHub -
[HIGH] Authenticated remote code execution in October CMS
PKSA-zpmz-wj2m-t91q CVE-2022-21705 GHSA-79jw-2f46-wv22
Affected version: >=2.0.0,<2.1.27|>=1.1.0,<1.1.10|<1.0.474
Reported by:
GitHub