Lucene search

K
osvGoogleOSV:CVE-2021-32648
HistoryAug 26, 2021 - 7:15 p.m.

CVE-2021-32648

2021-08-2619:15:07
Google
osv.dev
9
cve-2021-32648
octobercms
laravel
security
vulnerability
password reset
patched

AI Score

9.4

Confidence

High

EPSS

0.022

Percentile

89.6%

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

AI Score

9.4

Confidence

High

EPSS

0.022

Percentile

89.6%