← Back to CVEs
CVE-2021-29487
HIGH7.4
Description
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request. This only affects frontend users and the attacker must obtain a Laravel secret key for cookie encryption and signing in order to exploit this vulnerability. The issue has been patched in Build 472 and v1.1.5.
CVE Details
CVSS v3.1 Score7.4
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published8/26/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
octobercms:october
Weaknesses (CWE)
CWE-287
References
https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374(security-advisories@github.com)
https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9(security-advisories@github.com)
https://github.com/octobercms/october/security/advisories/GHSA-h76r-vgf3-j6w5(security-advisories@github.com)
https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/octobercms/october/security/advisories/GHSA-h76r-vgf3-j6w5(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.