#VU59616 Code Injection in October CMS - CVE-2021-32649

 

#VU59616 Code Injection in October CMS - CVE-2021-32649

Published: January 14, 2022


Vulnerability identifier: #VU59616
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-32649
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
October CMS
Software vendor:
OctoberCMS

Description

The vulnerability allows a remote user to execute arbitrary PHP code on the target system.

The vulnerability exists due to improper input validation. A remote user with "create, modify and delete website pages" privileges can execute PHP code by running specially crafted Twig code in the template markup.


Remediation

Install updates from vendor's website.

External links