Octobercms是美国Octobercms公司的一个基于Php的Cms建站系统。 octobercms october 存在安全漏洞,该漏洞源于在 october/system 软件包的受影响版本中,攻击者可以请求重置帐户密码,然后使用特制的请求访问帐户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| octobercms | october | >= 1.0.471, < 1.0.472 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof Of Concept code for OctoberCMS Auth Bypass CVE-2021-32648 | https://github.com/Immersive-Labs-Sec/CVE-2021-32648 | POC Details |
| 2 | Patch your code for October CMS Auth Bypass CVE-2021-32648 | https://github.com/daftspunk/CVE-2021-32648 | POC Details |
| 3 | octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/CVE-2021-32648.yaml | POC Details |
| 4 | octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-32648.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet