Improper Authorization in October CMS - CVE-2020-15128

 

Improper Authorization in October CMS - CVE-2020-15128

Published: July 31, 2020


Vulnerability identifier: #VU32948
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15128
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the application does not tie encrypted cookie value to cookie name. If the attacker is able to obtain encrypted cookies, it is possible to decrypt that information by supplying the encrypted cookie to the application and letting the application to decrypt it.


Affected software

October CMS

How to mitigate CVE-2020-15128

Install updates from vendor's website.

October CMS - update to 1.0.468

External References

Related Security Bulletins