5.2
CVSSv3

CVE-2021-21264

Published: 03/05/2021 Updated: 19/10/2022
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.2 | Impact Score: 3.7 | Exploitability Score: 1.1
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) exists that has the same impact as CVE-2020-26231 & CVE-2020-15247. An authenticated backend user with the `cms.manage_pages`, `cms.manage_layouts`, or `cms.manage_partials` permissions who would **normally** not be permitted to provide PHP code to be executed by the CMS due to `cms.enableSafeMode` being enabled is able to write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This is not a problem for anyone that trusts their users with those permissions to normally write & manage PHP within the CMS by not having `cms.enableSafeMode` enabled, but would be a problem for anyone relying on `cms.enableSafeMode` to ensure that users with those permissions in production do not have access to write & execute arbitrary PHP. Issue has been patched in Build 472 (v1.0.472) and v1.1.2. As a workaround, apply github.com/octobercms/october/commit/f63519ff1e8d375df30deba63156a2fc97aa9ee7 to your installation manually if unable to upgrade to Build 472 or v1.1.2.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

octobercms october

Github Repositories

CVE-2021-21264 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework A bypass of CVE-2020-26231 (fixed in 10470/471 and 111) was discovered that has the same impact as CVE-2020-26231 & CVE-2020-15247 An authenticated backend user with the cmsmanage_pages, cmsmanage_layouts, or cmsmanage_partials permissions who would normal