QID 730336

Date Published: 2022-02-02

QID 730336: OctoberCMS Account Reset Vulnerability

OctoberCMS is a CMS platform based on the Laravel PHP Framework.

The vulnerability allows account takeover by requesting an account password reset by sending specifically crafted packets.

Affected Versions:
OctoberCMS before Build 472 OctoberCMS before v1.1.5

QID Detection Logic (Unauthenticated):
The detection uses Blind Elephant for fingerprinting OctoberCMS versions.

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    The issue has been patched in Build 472 and v1.1.5.

    Workaround:
    Apply octobercms/library@016a297 and octobercms/library@5bd1a28 to your installation manually if you are unable to upgrade.

    CVEs related to QID 730336

    Software Advisories
    Advisory ID Software Component Link
    OctoberCMS URL Logo github.com/daftspunk/CVE-2021-32648