目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2021-21425— Grav 安全漏洞

一分钟漏洞结论

影响对象
getgrav grav-plugin-admin
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Grav是一套可扩展的用于个人博客、小型内容发布平台和单页产品展示的CMS(内容管理系统)。 Grav 存在安全漏洞,该漏洞源于未经身份验证的用户可以执行管理员控制器的一些方法,而不需要任何凭据。

CVSS 9.3 · Critical EPSS 80.60% · P100

公开利用映射 2

ExploitDB · 1 EDB-49788 [webapps]
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2021-21425 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
来源: CVE Program / CVE List V5
Vulnerability Description
Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any credentials. Particular method execution will result in arbitrary YAML file creation or content change of existing YAML files on the system. Successfully exploitation of that vulnerability results in configuration changes, such as general site information change, custom scheduler job definition, etc. Due to the nature of the vulnerability, an adversary can change some part of the webpage, or hijack an administrator account, or execute operating system command under the context of the web-server user. This vulnerability is fixed in version 1.10.8. Blocking access to the `/admin` path from untrusted sources can be applied as a workaround.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
来源: CVE Program / CVE List V5
Vulnerability Title
Grav 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Grav是一套可扩展的用于个人博客、小型内容发布平台和单页产品展示的CMS(内容管理系统)。 Grav 存在安全漏洞,该漏洞源于未经身份验证的用户可以执行管理员控制器的一些方法,而不需要任何凭据。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
getgrav grav-plugin-admin <= 1.10.7 -

二、漏洞 CVE-2021-21425 的公开POC

# POC 描述 源链接 神龙链接
1 GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425) https://github.com/CsEnox/CVE-2021-21425 POC详情
2 It is a nmap script for GravCMS vulnerability (CVE-2021-21425) https://github.com/frknktlca/GravCMS_Nmap_Script POC详情
3 working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln https://github.com/bluetoothStrawberry/cve-2021-21425 POC详情
4 It is a nmap script for GravCMS vulnerability (CVE-2021-21425) https://github.com/grey-master-a/GravCMS_Nmap_Script POC详情
5 None https://github.com/afifudinmtop/CVE-2021-21425 POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-21425 的情报信息

请登录查看更多情报信息。

CVE-2021-21425 厂商安全公告 (1)

CVE-2021-21425 公开利用代码 (2)

CVE-2021-21425 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2021-21425

暂无评论


发表评论