CVE-2021-29487: Authentication bypass in Octobercms
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request. This only affects frontend users and the attacker must obtain a Laravel secret key for cookie encryption and signing in order to exploit this vulnerability. The issue has been patched in Build 472 and v1.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-29487?
CVE-2021-29487 is a vulnerability in the October CMS server that allows unauthenticated users to bypass authentication and take over user accounts.
What is the severity of CVE-2021-29487?
CVE-2021-29487 has a severity rating of 7.4 (high).
How does CVE-2021-29487 affect October CMS?
CVE-2021-29487 affects the October CMS server, specifically the october/system package.
How can an attacker exploit CVE-2021-29487?
Attackers can exploit CVE-2021-29487 by exploiting the vulnerability to bypass authentication and take over user accounts on an October CMS server.
What is the fix for CVE-2021-29487?
To fix CVE-2021-29487, it is recommended to update the affected October CMS server to a version that includes the necessary security patches.