CVE-2021-32649

HIGH

October < 1.0.473 - Injection

Title source: rule
STIX 2.1

Description

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the backend is able to execute PHP code by running specially crafted Twig code in the template markup. The issue has been patched in Build 473 (v1.0.473) and v1.1.6. Those unable to upgrade may apply the patch to their installation manually as a workaround.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0050
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-74 CWE-94
Status published
Products (2)
october/system 1.1.0 - 1.1.6Packagist
octobercms/october < 1.0.473
Published Jan 14, 2022
Tracked Since Feb 18, 2026