Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. october/system
  4. ›
  5. CVE-2022-21705

CVE-2022-21705: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

February 23, 2022 (updated February 26, 2022)

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages can exploit this vulnerability to bypass cms.safe_mode / cms.enableSafeMode in order to execute arbitrary code. This issue only affects admin panels that rely on safe mode and restricted permissions. To exploit this vulnerability, an attacker must first have access to the backend area. The issue has been patched in Build 474 (v1.0.474) and v1.1.10.

References

  • github.com/advisories/GHSA-79jw-2f46-wv22
  • github.com/octobercms/library/commit/c393c5ce9ca2c5acc3ed6c9bb0dab5ffd61965fe
  • github.com/octobercms/october/security/advisories/GHSA-79jw-2f46-wv22
  • nvd.nist.gov/vuln/detail/CVE-2022-21705

Code Behaviors & Features

Detect and mitigate CVE-2022-21705 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.0.474, all versions starting from 1.1.0 before 1.1.10, all versions starting from 2.0.0 before 2.1.27

Fixed versions

  • 1.0.474
  • 1.1.10
  • 2.1.27

Solution

Upgrade to versions 1.0.474, 1.1.10, 2.1.27 or above.

Impact 7.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Source file

packagist/october/system/CVE-2022-21705.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 13 May 2025 12:14:16 +0000.