peter bassill · operator
$ cve CVE-2017-1000119 JSON

CVE-2017-1000119 EXPLOIT

7.2
HIGH · CVSS 3.0 · EPSS 61.3% (pctl 99)

Patch early

A public exploit exists.

Description

October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.

Scoring

CVSS7.2 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS61.35% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2017-10-05
Last modified2026-06-17

Affected (1)

VendorProduct
octobercmsoctober

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD