October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| october/october(Packagist) | 0 | 1.0.437 | N/A |
CVSS Metrics