Grav是一套可扩展的用于个人博客、小型内容发布平台和单页产品展示的CMS(内容管理系统)。 Grav 存在安全漏洞,该漏洞源于未经身份验证的用户可以执行管理员控制器的一些方法,而不需要任何凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getgrav | grav-plugin-admin | <= 1.10.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425) | https://github.com/CsEnox/CVE-2021-21425 | POC Details |
| 2 | It is a nmap script for GravCMS vulnerability (CVE-2021-21425) | https://github.com/frknktlca/GravCMS_Nmap_Script | POC Details |
| 3 | working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln | https://github.com/bluetoothStrawberry/cve-2021-21425 | POC Details |
| 4 | It is a nmap script for GravCMS vulnerability (CVE-2021-21425) | https://github.com/grey-master-a/GravCMS_Nmap_Script | POC Details |
| 5 | None | https://github.com/afifudinmtop/CVE-2021-21425 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet