PT-2021-18249 · October · October/System
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
october/system package versions prior to v1.1.5
october/system package versions prior to Build 472
Description:
The issue allows an attacker to bypass authentication and take over a user account on an October CMS server. This can be exploited by unauthenticated users via a specially crafted request, affecting only frontend users. To exploit this vulnerability, the attacker must obtain a Laravel secret key for cookie encryption and signing.
Recommendations:
For versions prior to v1.1.5, update to v1.1.5 or later to resolve the issue.
For versions prior to Build 472, update to Build 472 or later to resolve the issue.
As a temporary workaround, consider restricting access to sensitive areas of the October CMS server until the issue is resolved.
Avoid using the vulnerable
october/system package until the issue is resolved.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
October/System