← Back to CVE List
Vulnerability Intelligence Report
Account Takeover in Octobercms

CVE-2021-32648

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
8.2
HIGH
Exploitability:3.9
Impact Score:4.3
EPSS Probability:90.42%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-287 ↗CWE-287: Improper Authentication

Affected Products & Versions

Vendor Product Affected Versions
octobercms october >= 1.0.471, < 1.0.472 (affected), >= 1.1.1, < 1.1.5 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
90.418%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2021-05-12T00:00:00
Published2021-08-26T19:00:12
Last Updated2025-10-21T23:25:36

LINK COPIED TO CLIPBOARD