CVE-2022-24800: Race Condition in October CMS upload process

Published Jul 12, 2022
·
Updated

October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own filename in the fromData method, an unauthenticated user can perform remote code execution (RCE) by exploiting a race condition in the temporary storage directory. This vulnerability affects plugins that expose the October\Rain\Database\Attach\File::fromData as a public interface and does not affect vanilla installations of October CMS since this method is not exposed or used by the system internally or externally. The issue has been patched in Build 476 (v1.0.476), v1.1.12, and v2.2.15. Those who are unable to upgrade may apply with patch to their installation manually as a workaround.

Affected Software

3 affected components
October CMS Debugbar<1.0.476
October CMS Debugbar>=1.1.0<1.1.12
October CMS Debugbar>=2.0.0<2.2.15

Event History

Jul 12, 2022
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2022-24800?

CVE-2022-24800 is a vulnerability found in October/System, the system module for October CMS.

2

What is October CMS?

October CMS is a self-hosted CMS platform based on the Laravel PHP Framework.

3

What is the severity of CVE-2022-24800?

CVE-2022-24800 has a severity level of high (8.1).

4

How does CVE-2022-24800 affect October CMS?

CVE-2022-24800 affects October CMS versions 1.0.476, 1.1.0 to 1.1.12, and 2.0.0 to 2.2.15.

5

How can an unauthenticated user exploit CVE-2022-24800?

An unauthenticated user can exploit CVE-2022-24800 by performing remote code execution when the developer allows the user to specify their own filename in the `fromData` method.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203