#VU60799 Security features bypass in October CMS - CVE-2022-21705
Published: February 23, 2022
October CMS
OctoberCMS
Description
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to incorrect safe mode implementation. A remote authenticated user with permissions to create, modify and delete website pages can bypass cms.safe_mode or cms.enableSafeMode settings and execute arbitrary code on the server.