EXPOSURES › CVE-2021-32648
CVE-2021-32648
HIGH ⌖ ON CISA KEV · EXPLOITEDOctober CMS improper authentication flaw allowed attackers to bypass password reset and gain account access via crafted requests.
October CMS versions with the improper authentication flaw in the october/system package allowed attackers to request a password reset and then use a specially crafted request to gain unauthorized account access. DIB organizations must ensure their CMS platforms are patched to prevent account takeover and data breaches. This failure highlights the risk of relying on unpatched software with known authentication bypasses.
Shame score — A known authentication bypass in a widely used CMS that was actively exploited in the wild, indicating negligent patching and avoidable account compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.