S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-21705 Scanner

CVE-2022-21705 scanner - Code Injection vulnerability in Octobercms

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-21705
7.2
CVSShigh
Exploitable remotely over the internet · requires high privileges.

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages can exploit this vulnerability to bypass `cms.safe_mode` / `cms.enableSafeMode` in order to execute arbitrary code. This issue only affects admin panels that rely on safe mode and restricted permissions. To exploit this vulnerability, an attacker must first have access to the backend area. The issue has been patched in Build 474 (v1.0.474) and v1.1.10. Users unable to upgrade should apply https://github.com/octobercms/library/commit/c393c5ce9ca2c5acc3ed6c9bb0dab5ffd61965fe to your installation manually.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
octoberby octobercms
< 1.0.474
Updated Aug 22, 2026View on NVD →
Detail

Octobercms is a popular self-hosted content management system (CMS) based on Laravel PHP Framework. This platform is widely used for building websites, online stores, and various web applications. Its user-friendly interface and ease of customization make it highly desirable for web developers and non-programmers alike. 

However, a recent security vulnerability, CVE-2022-21705, has been identified in this platform. The vulnerability results from the fact that user input was not properly sanitized before rendering. Specifically, an authenticated user with the permissions to create, modify, and delete website pages can exploit this vulnerability to bypass `cms.safe_mode` / `cms.enableSafeMode` and execute arbitrary code.

Exploitation of this vulnerability can lead to serious consequences for website owners. Attackers can gain access to the backend area of websites and exploit this vulnerability to execute malicious code, implant backdoors, steal sensitive data, and even take full control over the affected websites. This vulnerability is particularly dangerous for admin panels that rely on safe mode and restricted permissions.

As a final point, by using the features of Securityforall.com, users can easily and quickly learn about vulnerabilities in their digital assets. The Pro version offers real-time monitoring, alerts, and reports to keep websites secure from vulnerabilities such as CVE-2022-21705. With Securityforall.com, users can ensure that their websites are secure, stay ahead of potential attacks, and protect their online assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, Octobercms users should take the following precautions:

  • Update to the latest patched version of the platform (Build 474 or v1.1.10)
  • Manually apply the patch provided on the official GitHub page if unable to upgrade
  • Monitor website access logs for suspicious behavior
  • Limit permissions of website users
  • Use a firewall to block unauthorized access to websites

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.