PT-2022-10089 · Unknown · October Cms

Cydave

+1

·

Published

2022-01-14

·

Updated

2022-08-05

·

CVE-2021-32649

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions October CMS versions prior to 1.0.473 and 1.1.6
Description The issue allows an attacker with "create, modify and delete website pages" privileges in the backend to execute PHP code by running specially crafted Twig code in the template markup.
Recommendations For versions prior to 1.0.473, update to version 1.0.473 or apply the patch to the installation manually as a workaround. For versions prior to 1.1.6, update to version 1.1.6 or apply the patch to the installation manually as a workaround.

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-32649
GHSA-WV23-PFJ7-2MJJ

Affected Products

October Cms