QID 730336
Date Published: 2022-02-02
QID 730336: OctoberCMS Account Reset Vulnerability
OctoberCMS is a CMS platform based on the Laravel PHP Framework.
The vulnerability allows account takeover by requesting an account password reset by sending specifically crafted packets.
Affected Versions:
OctoberCMS before Build 472
OctoberCMS before v1.1.5
QID Detection Logic (Unauthenticated):
The detection uses Blind Elephant for fingerprinting OctoberCMS versions.
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
Solution
The issue has been patched in Build 472 and v1.1.5.
Workaround:
Apply octobercms/library@016a297 and octobercms/library@5bd1a28 to your installation manually if you are unable to upgrade.
Vendor References
CVEs related to QID 730336
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OctoberCMS |
|