Code Injection in October CMS - CVE-2021-32649
Published: January 14, 2022
Vulnerability identifier: #VU59616
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32649
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary PHP code on the target system.
The vulnerability exists due to improper input validation. A remote user with "create, modify and delete website pages" privileges can execute PHP code by running specially crafted Twig code in the template markup.
Affected software
October CMS
How to mitigate CVE-2021-32649
Install updates from vendor's website.
October CMS - addressed in versions 1.0.473, 1.1.6