漏洞描述
October CMS is susceptible to remote code execution. In affected versions, user input is not properly sanitized before rendering. An authenticated user with the permissions to create, modify, and delete website pages can bypass cms.safe_mode and cms.enableSafeMode in order to execute arbitrary code. This affects admin panels that rely on safe mode and restricted permissions.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/octobercms/library/commit/c393c5ce9ca2c5acc3ed6c9bb0dab5ffd61965fe↗github.comhttps://github.com/octobercms/october/security/advisories/GHSA-79jw-2f46-wv22↗cyllective.comhttps://cyllective.com/blog/post/octobercms-cve-2022-21705/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-21705↗github.comhttps://github.com/cyllective/CVEs↗