SB2021100613 - Authorization bypass in October CMS
Published: October 6, 2021 Updated: May 26, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authorization (CVE-ID: CVE-2021-41126)
The vulnerability allows a remote user to compromise the affected application.
The vulnerability exists due to improper authorization. An attacker who previously had an administrative account with access to the admin interface is able to sign in to the backend using October CMS v2.0 even after the account has been deleted.
Remediation
Install update from vendor's website.