CVE-2017-16941: Malicious File Upload
DISPUTED October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by downloading a theme ZIP archive from /backend/cms/themes, and then uploading and importing a modified archive with two new files: a .php file and a .htaccess file. NOTE: the vendor says "I don't think [an attacker able to login to the system under an account that has access to manage/upload themes] is a threat model that we need to be considering."
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-16941.
What is the severity rating of CVE-2017-16941?
CVE-2017-16941 has a severity rating of 8.8 (high).
How does CVE-2017-16941 impact October CMS through 1.0.428?
CVE-2017-16941 allows remote authenticated users to execute arbitrary PHP code by uploading and importing a modified theme archive.
How can I mitigate the risk of CVE-2017-16941?
To mitigate the risk of CVE-2017-16941, ensure that you only download and use trusted theme ZIP archives in October CMS.
Is there a reference for more information about CVE-2017-16941?
Yes, you can find more information about CVE-2017-16941 at the following link: https://github.com/octobercms/october/issues/3257