目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2021-32648 PoC — Octobercms 安全漏洞

来源
关联漏洞
标题: Octobercms 安全漏洞 (CVE-2021-32648)
Description:Octobercms是美国Octobercms公司的一个基于Php的Cms建站系统。 octobercms october 存在安全漏洞,该漏洞源于在 october/system 软件包的受影响版本中,攻击者可以请求重置帐户密码,然后使用特制的请求访问帐户。
Description
Patch your code for October CMS Auth Bypass CVE-2021-32648
介绍
# CVE-2021-32648

Patch your code for October CMS Auth Bypass CVE-2021-32648

# Instructions

1. Open the file **vendor/october/rain/src/Auth/Models/User.php**
2. [Perform the patch found in these diff notes](https://github.com/daftspunk/CVE-2021-32648/commit/7dc2ce8b6d64a1954089aece560ef9f3e319b7a9)
3. Save the file

# Overview

You are converting a loose comparison to a strict comparison by replacing two (2) equal signs `==` with three (3) equal signs `===`. This blocks the attack vector as described in [CVE-2021-32648](https://github.com/octobercms/october/security/advisories/GHSA-mxr5-mc97-63rc) and also [CVE-2021-29487](https://github.com/octobercms/october/security/advisories/GHSA-h76r-vgf3-j6w5).

This issue has been patched in October CMS Build 472 (v1.0.472+) and v1.1.5+. This issue does not affect v2.0.0+.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →