CVE-2021-32648: Weak Password Recovery Mechanism for Forgotten Password
(updated )
octobercms in a CMS platform based on the Laravel PHP Framework. An attacker can request an account password reset and then gain access to the account using a specially crafted request.
References
Detect and mitigate CVE-2021-32648 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →