CVE-2021-41126

CVSS V2 Medium 6.5 CVSS V3 High 7.2
Description
October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts which had previously been deleted may still be able to sign in to the backend using October CMS v2.0. The issue has been patched in v2.1.12 of the october/october package. There are no workarounds for this issue and all users should update.
Overview
  • CVE ID
  • CVE-2021-41126
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2021-10-06T18:15:11
  • Last Modified Date
  • 2021-10-14T16:43:37
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* 1 OR 2.0.0 2.1.12
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:S/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • SINGLE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 6.5
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8
  • Impact Score
  • 6.4
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • HIGH
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 7.2
  • Base Severity
  • HIGH
  • Exploitability Score
  • 1.2
  • Impact Score
  • 5.9
References
Reference URL Reference Tags
https://github.com/octobercms/october/security/advisories/GHSA-6gjf-7w99-j7x7 Third Party Advisory
https://octobercms.com/changelog Release Notes Vendor Advisory
History
Created Old Value New Value Data Type Notes
2022-05-10 06:51:41 Added to TrackCVE
2022-12-05 11:56:38 2021-10-06T18:15Z 2021-10-06T18:15:11 CVE Published Date updated
2022-12-05 11:56:38 2021-10-14T16:43:37 CVE Modified Date updated
2022-12-05 11:56:38 Analyzed Vulnerability Status updated