CVE-2021-32648: October CMS Improper Authentication

Published Aug 26, 2021
·
Updated

Impact

An attacker can request an account password reset and then gain access to the account using a specially crafted request.

- To exploit this vulnerability, an attacker must know the username of an administrator and have access to the password reset form.

Patches

- Issue has been patched in Build 472 and v1.1.5 - Shortened patch instructions

Workarounds

Apply https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374 and https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9 to your installation manually if you are unable to upgrade.

[Update 2022-01-20] Shortened patch instructions can be found here.

Recommendations

We recommend the following steps to make sure your server stays secure:

- Keep server OS and system software up to date. - Keep October CMS software up to date. - Use a multi-factor authentication plugin. - Change the default backend URL or block public access to the backend area. - Include the Roave/SecurityAdvisories Composer package to ensure that your application doesn't have installed dependencies with known security vulnerabilities.

References

Bugs found as part of Solar Security CMS Research. Credits to: • Andrey Basarygin • Andrey Guzei • Mikhail Khramenkov • Alexander Sidukov • Maxim Teplykh

For more information If you have any questions or comments about this advisory: Email us at hello@octobercms.com

Other sources

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

CISA

Affected Software

6 affected componentsFixes available
composer/october/system>=1.1.1<1.1.5
1.1.5
composer/october/system<1.0.472
1.0.472
October CMS October CMS
Octobercms October>=1.0.471<1.0.472
Octobercms October>=1.1.1<1.1.5
Octobercms October=1.0.471

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/october/system to a version that resolves this vulnerability.

    Fixed in 1.1.5
  2. Upgrade

    Upgrade composer/october/system to a version that resolves this vulnerability.

    Fixed in 1.0.472
  3. Upgrade

    Upgrade octobercms/library to a version that resolves this vulnerability.

    Patch 016a297b1bec55d2e53bc889458ed2cb5c3e9374
  4. Upgrade

    Upgrade octobercms/library to a version that resolves this vulnerability.

    Patch 5bd1a28140b825baebe6becd4f7562299d3de3b9
  5. Configuration

    Change the default backend URL (see config/cms.php) to a non-default value or otherwise block public access to the backend area.

    October CMS default backend URL = change from default or block access
  6. Configuration

    Install and enable a multi-factor authentication plugin for backend accounts.

    October CMS MFA plugin = installed/enabled
  7. Configuration

    Include the Roave/SecurityAdvisories Composer package (require roave/security-advisories) to prevent installation of known-vulnerable dependencies.

    Composer require = roave/security-advisories
  8. Compensating control

    Restrict access to the October CMS backend (for example via firewall, WAF, or IP allowlist) to trusted IPs or internal networks; block public access to the backend area.

  9. Operational

    Keep server OS, system software, and October CMS installations up to date.

Event History

Aug 26, 2021
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 30, 2021
Advisory Published
via GitHub·04:13 PM
Jan 18, 2022
Known Exploited
via CISA·12:00 AM

Frequently Asked Questions

1

What is CVE-2021-32648?

CVE-2021-32648 is a vulnerability in October CMS that allows an attacker to gain unauthorized access to an account using a specially crafted request.

2

How can an attacker exploit CVE-2021-32648?

An attacker can exploit CVE-2021-32648 by requesting an account password reset and then gaining access to the account using a specially crafted request.

3

What is the severity of CVE-2021-32648?

CVE-2021-32648 has a severity rating of 9.1 (Critical).

4

Which versions of October CMS are affected by CVE-2021-32648?

Versions 1.0.471 to 1.0.472 and 1.1.1 to 1.1.5 of October CMS are affected by CVE-2021-32648.

5

How can I fix CVE-2021-32648?

CVE-2021-32648 has been patched in Build 472 and version 1.1.5 of October CMS, so updating to these versions will fix the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203