PT-2021-4044 · Unknown · Laravel Php Framework+1

Alexander Sidukov

+4

·

Published

2021-08-26

·

Updated

2025-10-24

·

CVE-2021-32648

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions October CMS versions prior to Build 472 and v1.1.5
Description The issue is related to an improper authentication mechanism in the October CMS platform, which is based on the Laravel PHP Framework. An attacker can exploit this by requesting an account password reset and then gaining access to the account using a specially crafted request.
Recommendations For versions prior to Build 472 and v1.1.5, update to Build 472 or v1.1.5 to resolve the issue. As a temporary workaround, consider restricting access to the account password reset feature until the update is applied.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2021-04572
CVE-2021-32648
GHSA-MXR5-MC97-63RC

Affected Products

Laravel Php Framework
October Cms