<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 22:35:51 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-04572</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-04572</link>
      <description>bdu:2021-04572</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-04572</guid>
    </item>
    <item>
      <title>EUVD-2026-255947</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255947</link>
      <description>EUVD-2026-255947</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255947</guid>
    </item>
    <item>
      <title>fkie_cve-2021-32648</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32648</link>
      <description>&lt;p&gt;octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-32648</guid>
    </item>
    <item>
      <title>GHSA-mxr5-mc97-63rc — Account Takeover in Octobercms</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mxr5-mc97-63rc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: october/system&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker can request an account password reset and then gain access to the account using a specially crafted request.&lt;/p&gt;
&lt;p&gt;- To exploit this vulnerability, an attacker must know the username of an administrator and have access to the password reset form.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;- Issue has been patched in Build 472 and v1.1.5
- [Shortened patch instructions](https://github.com/daftspunk/CVE-2021-32648)&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Apply https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374 and https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9 to your installation manually if you are unable to upgrade.&lt;/p&gt;
&lt;p&gt;[**Update 2022-01-20**] [Shortened patch instructions](https://github.com/daftspunk/CVE-2021-32648) can be found here.&lt;/p&gt;
&lt;p&gt;### Recommendations&lt;/p&gt;
&lt;p&gt;We recommend the following steps to make sure your server stays secure:&lt;/p&gt;
&lt;p&gt;- Keep server OS and system software up to date.
- Keep October CMS software up to date.
- Use a multi-factor authentication plugin.
- Change the [default backend URL](https://github.com/octobercms/october/blob/1.1/config/cms.php#L39) or block public access to the backend area.
- Include the [Roave/SecurityAdvisories](https://github.com/Roave/SecurityAdvisories) Composer package to ensure that your application doesn&amp;#39;t have installed dependencies with known security vulnerabilities.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;Bugs found as part of Solar Security CMS Research. Credits to:
• Andrey Basarygin
• Andrey Guzei
• Mikhail Khrame…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: october/system&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker can request an account password reset and then gain access to the account using a specially crafted request.&lt;/p&gt;
&lt;p&gt;- To exploit this vulnerability, an attacker must know the username of an administrator and have access to the password reset form.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;- Issue has been patched in Build 472 and v1.1.5
- [Shortened patch instructions](https://github.com/daftspunk/CVE-2021-32648)&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Apply https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374 and https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9 to your installation manually if you are unable to upgrade.&lt;/p&gt;
&lt;p&gt;[**Update 2022-01-20**] [Shortened patch instructions](https://github.com/daftspunk/CVE-2021-32648) can be found here.&lt;/p&gt;
&lt;p&gt;### Recommendations&lt;/p&gt;
&lt;p&gt;We recommend the following steps to make sure your server stays secure:&lt;/p&gt;
&lt;p&gt;- Keep server OS and system software up to date.
- Keep October CMS software up to date.
- Use a multi-factor authentication plugin.
- Change the [default backend URL](https://github.com/octobercms/october/blob/1.1/config/cms.php#L39) or block public access to the backend area.
- Include the [Roave/SecurityAdvisories](https://github.com/Roave/SecurityAdvisories) Composer package to ensure that your application doesn&amp;#39;t have installed dependencies with known security vulnerabilities.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;Bugs found as part of Solar Security CMS Research. Credits to:
• Andrey Basarygin
• Andrey Guzei
• Mikhail Khrame…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mxr5-mc97-63rc</guid>
    </item>
    <item>
      <title>gsd-2021-32648</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-32648</link>
      <description>gsd-2021-32648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-32648</guid>
    </item>
  </channel>
</rss>
