CVE-2017-1000119 describes a critical PHP code execution vulnerability in October CMS build 412, specifically within its file upload functionality. This flaw, rated 7.2 HIGH, allows authenticated attackers to execute arbitrary code, leading to complete site compromise and potential impact on other server applications. While not on the KEV catalog or Hot List, a Metasploit module exists for this exploit, indicating readily available exploit code. Despite the high risk, there is no evidence of active exploitation, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.412CPE matchmatch criteria | cpe:2.3:a:octobercms:october:1.0.412:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.