GHSA-6gjf-7w99-j7x7
Dashboard / Vulnerabilities / GHSA-6gjf-7w99-j7x7
Summary: Deleted Admin Can Sign In to Admin Interface
Details: ### Impact Assuming an administrator once had previous access to the admin interface, they may still be able to sign in to the backend using October CMS v2.0. ### Patches The issue has been patched in v2.1.12 ### Workarounds - Reset the password of the deleted accounts to prevent them from signing in. - Please contact [email protected] for code change instructions if you are unable to upgrade. ### References Credits to: • Daniel Bidala ### For more information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected])
References: https://github.com/octobercms/october/security/advisories/GHSA-6gjf-7w99-j7x7, https://nvd.nist.gov/vuln/detail/CVE-2021-41126, https://github.com/octobercms/october, https://octobercms.com/changelog
Affected packages
Package
Name: october/october
Purl: pkg:composer/october/october
Affected ranges
Type: ECOSYSTEM
Events:
