SB2021100613 - Authorization bypass in October CMS



SB2021100613 - Authorization bypass in October CMS

Published: October 6, 2021 Updated: May 26, 2022

Security Bulletin ID SB2021100613
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authorization (CVE-ID: CVE-2021-41126)

The vulnerability allows a remote user to compromise the affected application.

The vulnerability exists due to improper authorization. An attacker who previously had an administrative account with access to the admin interface is able to sign in to the backend using October CMS v2.0 even after the account has been deleted.


Remediation

Install update from vendor's website.