vulnerability
October CMS: CVE-2021-32648: Improper Authentication
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:C/I:P/A:N) | Aug 26, 2021 | Sep 2, 2025 | Sep 2, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:P/A:N)
Published
Aug 26, 2021
Added
Sep 2, 2025
Modified
Sep 2, 2025
Description
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.
Solution
october-cms-upgrade-latest
References
- CVE-2021-32648
- https://attackerkb.com/topics/CVE-2021-32648
- URL-https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374
- URL-https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9
- URL-https://github.com/octobercms/october/security/advisories/GHSA-mxr5-mc97-63rc
- CWE-287
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.