Improper Authorization in October CMS - CVE-2021-41126

 

Improper Authorization in October CMS - CVE-2021-41126

Published: October 6, 2021 / Updated: May 26, 2022


Vulnerability identifier: #VU57098
CSH Severity: Medium
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-41126
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the affected application.

The vulnerability exists due to improper authorization. An attacker who previously had an administrative account with access to the admin interface is able to sign in to the backend using October CMS v2.0 even after the account has been deleted.


Affected software

October CMS

How to mitigate CVE-2021-41126

Install updates from vendor's website.

October CMS - update to 2.1.12

External References

Related Security Bulletins