CVE-2021-32648
26.08.2021, 19:15
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.Enginsight
Vendor | Product | Version |
---|---|---|
octobercms | october | 1.1.1 ≤ 𝑥 < 1.1.5 |
octobercms | october | 1.0.471 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References