Vulnerability record · CVE-2017-1000119 · published 5 October 2017
CVE-2017-1000119: October CMS file upload flaw allows PHP code execution
Octobercms · October
October CMS build 412 permits unrestricted file uploads that lead to PHP code execution. An attacker who can reach the upload functionality can place executable code on the server, compromising the site and potentially other applications on the same host.
Description
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw yields code execution and has a very high EPSS score, though exploitation requires high privileges and no KEV listing exists.
What it is
October CMS build 412 permits unrestricted file uploads that lead to PHP code execution. An attacker who can reach the upload functionality can place executable code on the server, compromising the site and potentially other applications on the same host.
Impact
Successful exploitation gives the attacker arbitrary PHP code execution in the web server context, enabling full site compromise and possible lateral impact on other applications on the server.
Attack surface
Reached over the network through the file upload functionality; the CVSS vector indicates high privileges are required (PR:H) and no user interaction is needed (UI:N).
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high (0.61347, 99.123rd percentile) and a public Packet Storm advisory describes an upload protection bypass with code execution.
What to do
- Upgrade October CMS past build 412 per the vendor advisory (rn-8).
- Restrict upload functionality to trusted, authenticated administrative users only.
- Enforce server-side validation of file type and extension and store uploads outside the web root.
- Disable PHP execution in upload directories and apply least privilege to the web server user.
- Monitor the vendor advisory for further guidance if upgrading is delayed.
Detection
- Alert on PHP files or other executable content appearing in upload directories.
- Review web server logs for POST requests to upload endpoints followed by requests to newly written files.
- Monitor for unexpected child processes spawned by the web server user.
- Audit file integrity in web-accessible directories for new or modified scripts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-1000119 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-1000119), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.