Web Vulnerability Report
ID | EDB-ID-49961 |
CVSS 3.0 | 7.2 |
Cloudbric Score
?
|
Medium |
Cloudbric Detection | Yes |
Vulnerability Type | SSTI |
Published Date | 2021-06-07 |
Updated Date | 2021-07-21 |
Vendor | N/A,1.7.10 |
Description | Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. The issue was addressed in version 1.7.11. |
Reference | N/AGrav CMS 1.7.10 - Server-Side Template Injection (SSTI) (Authenticated) |
URL Link | https://www.exploit-db.com/exploits/49961/ |
This vulnerability has been detected by Cloudbric!
Block NOW!
ID | Description | Vulnerability Type |
Cloudbric Score
?
|
Updated Date | Detection |
---|
To receive weekly updates on new vulnerabilities added to Threat Index
Subscribe Now