Impact
October CMS prior to v3.7.17 and v4.2.21 stored widget session data with base64(serialize(...)) and later unserialised it without protecting against arbitrary class instantiation. When the CMS runs with its optional Safe Mode enabled, an attacker who can write to a widget.* session key can supply a crafted payload that triggers PHP object injection upon the next widget read. This flaw can be leveraged to instantiate arbitrary classes, enabling gadget execution or other severe compromises. The CVSS score of 3.3 reflects the narrow scope of the problem because only installations that enable Safe Mode and have untrusted users with markup-editor access are potentially vulnerable.
Affected Systems
The vulnerability affects October CMS managed by the Octobercms project. v3.7.17 or v4.2.21 that have the cms.safe_mode option turned on are impacted. In most production deployments Safe Mode is disabled and administrator access is restricted, so the affected user base is limited.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, and the EPSS score is < 1%, and it is not listed in the CISA KEV catalog. Exploitation requires an attacker to first gain the ability to write session data in a Safe Mode context and also to have a usable PHP gadget chain from the installed dependencies mainly for demo and multi-tenant scenarios, the practical risk remains low, but the flaw can still be dangerous in those environments.
OpenCVE Enrichment
Github GHSA