Executive brief
An improper authentication vulnerability in October CMS allows an attacker to gain unauthorized access to an account. By requesting a password reset and providing a specially crafted request, the attacker can bypass authentication mechanisms.
Affected products
- October CMS October CMS >= 1.0.471, < 1.0.472; >= 1.1.1, < 1.1.5
Timeline
- 2021-08-26: disclosed: Initial advisory publication date (implied by CVE ID and GitHub advisory)
- 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-18: disclosed: NVD publication date
- 2021-08-26: patched: Patched in Build 472 and v1.1.5
- exploited: Reported as exploited in the wild and listed in CISA KEV catalog.