Skip to content

Deleted Admin Can # to Admin Interface

Moderate
daftspunk published GHSA-6gjf-7w99-j7x7 Oct 6, 2021

Package

composer october/system (Composer)

Affected versions

>2.1

Patched versions

2.1.12

Description

Impact

Assuming an administrator once had previous access to the admin interface, they may still be able to # to the backend using October CMS v2.0.

Patches

The issue has been patched in v2.1.12

Workarounds

  • Reset the password of the deleted accounts to prevent them from signing in.

  • Please contact hello@octobercms.com for code change instructions if you are unable to upgrade.

References

Credits to:
• Daniel Bidala

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2021-41126

Weaknesses

No CWEs