Code Injection in October CMS - CVE-2021-32649

 

Code Injection in October CMS - CVE-2021-32649

Published: January 14, 2022


Vulnerability identifier: #VU59616
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32649
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary PHP code on the target system.

The vulnerability exists due to improper input validation. A remote user with "create, modify and delete website pages" privileges can execute PHP code by running specially crafted Twig code in the template markup.


Affected software

October CMS

How to mitigate CVE-2021-32649

Install updates from vendor's website.

October CMS - addressed in versions 1.0.473, 1.1.6

External References

Related Security Bulletins