Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. october/backend
  4. ›
  5. CVE-2020-15248

CVE-2020-15248: Improper Privilege Management

November 23, 2020 (updated November 19, 2021)

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default “Publisher” system role have access to create & manage users where they can choose which role the new user has. This means that a user with “Publisher” access has the ability to escalate their access to “Developer” access. Issue has been patched in Build 470 (v1.0.470) & v1.1.1.

References

  • github.com/advisories/GHSA-rfjc-xrmf-5vvw
  • github.com/octobercms/october/commit/4c650bb775ab849e48202a4923bac93bd74f9982
  • github.com/octobercms/october/commit/78a37298a4ed4602b383522344a31e311402d829
  • github.com/octobercms/october/security/advisories/GHSA-rfjc-xrmf-5vvw
  • nvd.nist.gov/vuln/detail/CVE-2020-15248

Code Behaviors & Features

Detect and mitigate CVE-2020-15248 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.0.319 before 1.0.470

Fixed versions

  • 1.0.470

Solution

Upgrade to version 1.0.470 or above.

Impact 4.2 MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-269: Improper Privilege Management

Source file

packagist/october/backend/CVE-2020-15248.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:26 +0000.