{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-07T23:55:20.518","vulnerabilities":[{"cve":{"id":"CVE-2021-29487","sourceIdentifier":"security-advisories@github.com","published":"2021-08-26T19:15:07.160","lastModified":"2024-11-21T06:01:14.430","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request. This only affects frontend users and the attacker must obtain a Laravel secret key for cookie encryption and signing in order to exploit this vulnerability. The issue has been patched in Build 472 and v1.1.5."},{"lang":"es","value":"octobercms en una plataforma CMS basada en el framework PHP Laravel. En las versiones afectadas del paquete october/system un atacante puede explotar esta vulnerabilidad para omitir la autenticación y hacerse con una cuenta de usuario en un servidor de October CMS. La vulnerabilidad puede ser explotada por usuarios no autenticados por medio de una petición especialmente diseñada. Esto sólo afecta a usuarios del frontend y el atacante debe obtener una clave secreta de Laravel para el cifrado y la firma de cookies con el fin de explotar esta vulnerabilidad. El problema ha sido parcheado en el Build 472 y en la versión v1.1.5."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.471","versionEndExcluding":"1.0.472","matchCriteriaId":"32CA477B-7437-4DB8-891D-05E1297E36FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*","versionStartIncluding":"1.1.1","versionEndExcluding":"1.1.5","matchCriteriaId":"2E79163B-046D-4BA9-82C9-70AB3A000D69"}]}]}],"references":[{"url":"https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/octobercms/october/security/advisories/GHSA-h76r-vgf3-j6w5","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/octobercms/october/security/advisories/GHSA-h76r-vgf3-j6w5","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]}]}}]}