Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-5297
PHP vulnerability analysis and mitigation

Overview

CVE-2020-5297 affects OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466. The vulnerability allows an authenticated backend user with 'cms.manage_assets' permission to upload various file types (including jpg, jpeg, bmp, png, webp, gif, ico, css, js, woff, woff2, svg, ttf, eot, json, md, less, sass, scss, xml) to any directory on an October CMS server (GitHub Advisory).

Technical details

The vulnerability exists in the functionality that lets a user with 'Manage website assets' permission to move assets from one folder to another. The issue stems from the onMove() function defined in modules/cms/widgets/AssetList.php:305, where the $destinationDir variable is initiated directly from the 'dest' parameter without proper validation. This allows moving files from the assets folder to any directory in the server (Full Disclosure).

Impact

An attacker with the required permissions can exploit this vulnerability to upload whitelisted file types to any directory on the October CMS server. This could potentially lead to security implications depending on the types of files uploaded and their locations (GitHub Advisory).

Exploitability

The vulnerability requires an authenticated backend user with the specific 'cms.manage_assets' permission to exploit. The attack can be executed by modifying the 'dest' parameter in the request sent to the server for moving an asset file (Full Disclosure).

Mitigation and workarounds

The vulnerability has been patched in Build 466 (v1.0.466). For users unable to upgrade, they can manually apply the patch 6711dae to their installation, which improves asset file path handling when moving assets. The patch includes validation of the destination path to ensure it remains within the safe directory (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71537MEDIUM6.5
  • PHP logoPHP
  • paymenter/paymenter
NoYesSep 18, 2026
CVE-2026-77616MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77610MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77609MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77608MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management