You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attackers with Editor access could inject patterns such as ${APP_KEY} or ${DB_PASSWORD} into CMS page settings fields, causing sensitive environment variables to be resolved, stored in the template, and returned to the attacker when the page was reopened. This could enable exfiltration of credentials and secrets (database passwords, AWS keys, application keys), potentially leading to further attacks such as database access or cookie forgery. The vulnerability is only relevant when cms.safe_mode is enabled, as direct PHP injection is already possible otherwise. This issue has been fixed in versions 3.7.14 and 4.1.10. If users are unable to immediately upgrade, they can workaround this issue by restricting Editor tool access to fully trusted administrators only, and ensuring database and cloud service credentials are not accessible from the web server's network.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: October CMS de Octobercms, Description: October es un Sistema de Gestión de Contenidos (CMS) y plataforma web. Las versiones anteriores a la 3.7.14 y 4.1.10 contienen una vulnerabilidad de revelación de información del lado del servidor en el analizador de configuraciones INI. Debido a que la función parse_ini_string() de PHP soporta la sintaxis ${} para la interpolación de variables de entorno, los atacantes con acceso de Editor podrían inyectar patrones como ${APP_KEY} o ${DB_PASSWORD} en los campos de configuración de las páginas del CMS, haciendo que las variables de entorno sensibles se resolvieran, se almacenaran en la plantilla y se devolvieran al atacante cuando la página se volvía a abrir. Esto podría permitir la exfiltración de credenciales y secretos (contraseñas de base de datos, claves de AWS, claves de aplicación), lo que podría conducir a ataques adicionales como el acceso a la base de datos o la falsificación de cookies. La vulnerabilidad solo es relevante cuando cms.safe_mode está habilitado, ya que la inyección directa de PHP ya es posible de otra manera. Este problema ha sido solucionado en las versiones 3.7.14 y 4.1.10. Si los usuarios no pueden actualizar de inmediato, pueden solucionar este problema restringiendo el acceso a la herramienta de Editor solo a administradores de plena confianza y asegurándose de que las credenciales de la base de datos y los servicios en la nube no sean accesibles desde la red del servidor web.
OR
*cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* versions up to (excluding) 3.7.14
*cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.1.10
New CVE Received from GitHub, Inc.4/14/2026 5:16:25 PM
Action
Type
Old Value
New Value
Added
Description
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attackers with Editor access could inject patterns such as ${APP_KEY} or ${DB_PASSWORD} into CMS page settings fields, causing sensitive environment variables to be resolved, stored in the template, and returned to the attacker when the page was reopened. This could enable exfiltration of credentials and secrets (database passwords, AWS keys, application keys), potentially leading to further attacks such as database access or cookie forgery. The vulnerability is only relevant when cms.safe_mode is enabled, as direct PHP injection is already possible otherwise. This issue has been fixed in versions 3.7.14 and 4.1.10. If users are unable to immediately upgrade, they can workaround this issue by restricting Editor tool access to fully trusted administrators only, and ensuring database and cloud service credentials are not accessible from the web server's network.