SB2020073108 - Authorization bypass in October CMS
Published: July 31, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authorization (CVE-ID: CVE-2020-15128)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the application does not tie encrypted cookie value to cookie name. If the attacker is able to obtain encrypted cookies, it is possible to decrypt that information by supplying the encrypted cookie to the application and letting the application to decrypt it.
Remediation
Install update from vendor's website.