Grav是一套可扩展的用于个人博客、小型内容发布平台和单页产品展示的CMS(内容管理系统)。 Grav 1.7.42之前版本存在代码注入漏洞,该漏洞源于存在服务器端模板注入 (SSTI)漏洞,允许攻击者通过在管理员屏幕上嵌入恶意PHP代码来实现远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-34448 | 8.8 HIGH | Grav Server-side Template Injection (SSTI) via Twig Default Filters |
| CVE-2023-34253 | 8.8 HIGH | Grav vulnerable to Server-side Template Injection (SSTI) via Denylist Bypass |
| CVE-2023-34252 | 8.8 HIGH | Grav Server-side Template Injection via Insufficient Validation in filterFilter |
| CVE-2023-34452 | 5.4 MEDIUM | Grav vulnerable to Self Cross Site Scripting in /forgot_password |
No comments yet