Junglewise Threat Intelligence

CVE-2021-32648: Account Takeover in Octobercms

CVE-2021-32648 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2021-08-30

Technologies: October CMS. Vendors: October CMS.

Executive brief

An improper authentication vulnerability in October CMS allows an attacker to gain unauthorized access to an account. By requesting a password reset and providing a specially crafted request, the attacker can bypass authentication mechanisms.

Affected products

  • October CMS October CMS >= 1.0.471, < 1.0.472; >= 1.1.1, < 1.1.5

Timeline

  • 2021-08-26: disclosed: Initial advisory publication date (implied by CVE ID and GitHub advisory)
  • 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-18: disclosed: NVD publication date
  • 2021-08-26: patched: Patched in Build 472 and v1.1.5
  • exploited: Reported as exploited in the wild and listed in CISA KEV catalog.

Related threats