Grav是一套可扩展的用于个人博客、小型内容发布平台和单页产品展示的CMS(内容管理系统)。 Grav 1.7.45 版本之前存在安全漏洞,该漏洞源于容易受到服务器端模板注入 (SSTI) 的攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof of Concept script to exploit the authenticated SSTI+RCE in Grav CMS (CVE-2024-28116) | https://github.com/akabe1/Graver | POC Details |
| 2 | Exploit against Grav CMS (versions below 1.7.45) that allows Remote Code Execution for an authenticated user - CVE-2024-28116 | https://github.com/gunzf0x/Grav-CMS-RCE-Authenticated | POC Details |
| 3 | is a PoC Python script that exploits an authenticated Server-Side Template Injection (SSTI) vulnerability in Grav CMS versions <= 1.7.44 (CVE-2024-28116) | https://github.com/geniuszlyy/GenGravSSTIExploit | POC Details |
| 4 | is a PoC Python script that exploits an authenticated Server-Side Template Injection (SSTI) vulnerability in Grav CMS versions <= 1.7.44 (CVE-2024-28116) | https://github.com/geniuszly/GenGravSSTIExploit | POC Details |
| CVE-2024-28119 | 8.8 HIGH | Grav vulnerable to Server Side Template Injection (SSTI) via Twig escape handler |
| CVE-2024-28118 | 8.8 HIGH | Grav vulnerable to Server Side Template Injection (SSTI) |
| CVE-2024-28117 | 8.8 HIGH | Grav vulnerable to Server Side Template Injection (SSTI) |
| CVE-2024-27921 | 8.8 HIGH | Grav File Upload Path Traversal vulnerability |
No comments yet