An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session ID is known to an attacker.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOctobercms October
APPOctobercms≤ 1.0.471
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2023-44382CRITICAL9.1PL ✓same product
October CMS — ucieczka z piaskownicy Twig i wykonanie arbitralnego PHP
CVE-2017-1000197CRITICAL9.8PL ✓same product
October CMS – manipulacja ścieżką pliku w funkcji przenoszenia zasobów
CVE-2017-1000196CRITICAL9.8PL ✓same product
October CMS — zdalne wykonanie kodu PHP w menedżerze plików
CVE-2017-1000194CRITICAL9.8PL ✓same product
October CMS: modyfikacja konfiguracji Apache przez niebezpieczny upload pliku
CVE-2021-32648HIGH8.2⚠ KEVsame product
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system pa...