← Back to browse · API

CVE-2021-32648

Severity
HIGH
CVSS
8.2
EPSS
0.90418
Risk score
56.65
CISA KEV
Yes
PoC
No
Published
2021-08-26
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-1808, GHSA-MXR5-MC97-63RC
Products
October CMS:October CMS, octobercms:October 1.0.471, < 1.0.472, octobercms:October 1.1.1, < 1.1.5
Sources
cisa.gov CVE-2021-32648
euvd EUVD-2021-1808

Description

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

References