CVE-2021-32648
Account Takeover in Octobercms
- Published
- Aug 26, 2021
- Updated
- Oct 21, 2025
- Assigning CNA
- GitHub_M
- Evidence observed
- Jan 18, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHigh · next 30 days
- Percentile
- 99.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.
Sources
2- CVE-2021-32648Patch
Provides a manual patch for October CMS authentication bypass vulnerabilities CVE-2021-32648 and CVE-2021-29487 by converting loose to strict comparisons in User.php.
Proof-of-concept exploit for OctoberCMS authentication bypass (CVE-2021-32648), demonstrating unauthorized access and providing a working PoC for security testing.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.