CVE-2020-5295 is an authenticated local file read vulnerability affecting OctoberCMS versions from 1.0.319 up to, but not including, 1.0.466. An attacker with backend access and 'cms.manage_assets' permission can exploit this to read arbitrary files on the server. Rated Medium severity (CVSS 4.9), the exploit requires high privileges but has a high impact on confidentiality. While not on the KEV catalog, a public exploit is available on ExploitDB, though there is no evidence of widespread active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.319, < 1.0.466CPE matchmatch criteria | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.