Impact
October CMS uses a Twig sandbox when cms.safe_mode is enabled. In affected versions prior to 3.7.17 and 4.2.21, a backend user with CMS markup editing rights can exploit an unrestricted session store and raw SQL access to read arbitrary database values and write to the authentication session key. This allows the attacker to forge a session as any existing user, granting unauthorized administrative access and exposure of confidential data. The flaw is confined to sites that deliberately enable Safe Mode for demo or untrusted‑editor scenarios, making the overall impact narrow but serious for this niche use case.
Affected Systems
OctoberCMS System module, versions earlier than 3.7.17 (for the 3.x line) and 4.2.21 (for the 4.x line). The vulnerability is only triggered when cms.safe_mode is enabled and a backend user with CMS markup editing permissions has access, and when at least one superuser account exists that can be impersonated.
Risk and Exploitability
The CVSS score of 3.3 reflects low severity, and the EPSS score is reported as < 1%, indicating a very low likelihood of exploitation in the general population. The risk is not listed in the CISA KEV catalog. Exploitation requires a site to have Safe Mode enabled, a backend user with markup editing rights, and a superuser account; if these conditions are met, the attacker can read database values and hijack sessions. Consequently, the overall risk is considered low for most deployments but significant for environments that intentionally use Safe Mode for untrusted editors.
OpenCVE Enrichment
Github GHSA