October CMS Improper Authentication
Vendor: October CMS
Product: October CMS
Added: 2022-01-18
Due Date: 2022-02-01
Description:
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
Required Action:
Apply updates per vendor instructions.
CWEs: