CVE-2021-32648 is a critical account takeover vulnerability affecting October CMS (october/system package) versions prior to Build 472 and v1.1.5. An unauthenticated attacker can exploit this flaw by initiating a password reset and then using a specially crafted request to gain unauthorized access to user accounts. With a CVSS score of 9.1 (Critical), this vulnerability allows for complete compromise of confidentiality and integrity with no user interaction required. This CVE is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community attention and media coverage, including its use in attacks against Ukrainian government websites.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.1, < 1.1.5CPE matchmatch criteria | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* | ||
1.0.471CPE matchmatch criteria | cpe:2.3:a:octobercms:october:1.0.471:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.