Vulnerabilities > CVE-2017-1000195 - Deserialization of Untrusted Data vulnerability in Octobercms October

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
octobercms
CWE-502

Summary

October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.

Vulnerable Configurations

Part Description Count
Application
Octobercms
307

Common Weakness Enumeration (CWE)