CVE-2017-1000197

EUVD-2017-1474
October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
octobercmsoctober
𝑥
≤ 1.0.412
𝑥
= Vulnerable software versions
Common Weakness Enumeration