#VU56118 Weak Password Recovery Mechanism for Forgotten Password in October CMS - CVE-2021-32648
Published: August 26, 2021 / Updated: February 20, 2022
October CMS
OctoberCMS
Description
The vulnerability allows a remote attacker to compromise the affected application.
The vulnerability exists due to a weak password recovery mechanism. A remote attacker can send a specially crafted request to the web application, reset password for an arbitrary account and gain unauthorized access to the application.