{"cvss":8.2,"datePublished":"2022-01-18","dateUpdated":"2022-01-18","description":"In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.","dueDate":"2022-02-01","id":"CVE-2021-32648","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-32648","product":"October CMS","requiredAction":"Apply updates per vendor instructions.","severity":"HIGH","source":"cisa_known_exploited","title":"October CMS Improper Authentication","vendor":"October CMS"}