Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-15246

Description

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1.0.469, an attacker can read local files on an October CMS server via a specially crafted request. Issue has been patched in Build 469 (v1.0.469) and v1.1.0.

POC

Reference

- https://github.com/octobercms/library/commit/80aab47f044a2660aa352450f55137598f362aa4

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/cyb3r-w0lf/nuclei-template-collection