CVE-2018-1999009: Infoleak
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.
Other sources
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend path is accessible. This vulnerability appears to have been fixed in Build 437.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1999009?
CVE-2018-1999009 is a vulnerability in October CMS version prior to Build 437 that allows for local file inclusion and sensitive information disclosure.
How severe is CVE-2018-1999009?
CVE-2018-1999009 has a severity rating of 8.1 (high).
Which software versions are affected by CVE-2018-1999009?
October CMS versions prior to Build 437 are affected by CVE-2018-1999009.
How can I fix CVE-2018-1999009?
To fix CVE-2018-1999009, update October CMS to at least Build 437.
Where can I find more information about CVE-2018-1999009?
You can find more information about CVE-2018-1999009 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-1999009), [October CMS Release Notes](http://octobercms.com/support/article/rn-10), [GitHub Security Advisory](https://github.com/advisories/GHSA-v7cr-w5v6-6659).