CompositeC1.Core
C1 CMS Foundation - a .NET based Web Content Management System, open source and a bundle of joy! Orckestra is the company driving the development of C1 CMS Foundation. We have a team working full time on this CMS and on other cool stuff you can add to it. We are situated in Montreal, Copenhagen and Kiev. We specialize in enterprise omni channel commerce software.
Activity
- Latest release
- 3y ago
- Total releases
- 24
- Cadence
- ~4 months
- Last 12 months
- 0
Details
- First release
- Nov 13, 2014
| Version | Released | |
|---|---|---|
6.13.0
minor
| ||
6.12.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.11.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.10.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.9.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.8.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.7.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.6.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.5.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.4.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.3.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.2.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.1.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
6.0.0
major
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.5.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.4.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.3.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.2.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev |
5.2.0
minor
Dependencies (5)
Changelog
Compare changes
|
|
5.1.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev |
5.1.0
minor
Dependencies (5)
Changelog
Compare changes
|
|
5.0.0
major
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev |
5.0.0
major
Dependencies (5)
Changelog
Compare changes
|
|
4.3.0
minor
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
4.3.0-beta1
pre
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
4.2.1
patch
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
4.2.0
initial
1 CVE
CVE-2022-39256
GHSA-gfhp-jgp6-838j
Sep 30, 2022
Orckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
ImpactThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. PatchesPatched in C1 CMS v6.13 WorkaroundsUpgrade to C1 CMS v6.13 or newer is required CreditThis issue was discovered and reported by Markus Wulftange / Code White GmbH. Affected versions
4.2.0
4.2.1
4.3.0
4.3.0-beta1
5.0.0
5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
6.0.0
6.1.0
+ 11 more Show less
6.10.0
6.11.0
6.12.0
6.2.0
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.8.0
6.9.0
Fixed in
6.13
References
Updated Nov 08, 2023 · Source: OSV.dev |