CVE-2020-15248Incorrect Authorization in October

Severity
4.2MEDIUMNVD
EPSS
0.0%
top 84.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23

Description

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have access to create & manage users where they can choose which role the new user has. This means that a user with "Publisher" access has the ability to escalate their access to "Developer" access. Issue has been patched in Build 470 (v1.0.470) & v1.1.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LExploitability: 0.8 | Impact: 3.4

Affected Packages3 packages

Packagistoctober/backend1.0.3191.0.470
NVDoctobercms/october1.0.3191.0.469
CVEListV5octobercms/october>= 1.0.319, < 1.0.470

Patches

🔴Vulnerability Details

2
OSV
Privilege escalation by backend users assigned to the default "Publisher" system role2020-11-23
GHSA
Privilege escalation by backend users assigned to the default "Publisher" system role2020-11-23