SB2022022302 - Security restrictions bypass in October CMS
Published: February 23, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security features bypass (CVE-ID: CVE-2022-21705)
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to incorrect safe mode implementation. A remote authenticated user with permissions to create, modify and delete website pages can bypass cms.safe_mode or cms.enableSafeMode settings and execute arbitrary code on the server.
Remediation
Install update from vendor's website.