vulnerability

October CMS: CVE-2021-32648: Improper Authentication

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:P/A:N)
Published
Aug 26, 2021
Added
Sep 2, 2025
Modified
Sep 2, 2025

Description

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

Solution

october-cms-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.