Grav是一套可扩展的用于个人博客、小型内容发布平台和单页产品展示的CMS(内容管理系统)。 Grav 1.7.45 版本之前存在安全漏洞,该漏洞源于通过Utils::isDangerousFunction函数验证可访问的函数,但不对twig_array_map等twig函数施加限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-28119 | 8.8 HIGH | Grav vulnerable to Server Side Template Injection (SSTI) via Twig escape handler |
| CVE-2024-28118 | 8.8 HIGH | Grav vulnerable to Server Side Template Injection (SSTI) |
| CVE-2024-28116 | 8.8 HIGH | Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass |
| CVE-2024-27921 | 8.8 HIGH | Grav File Upload Path Traversal vulnerability |
No comments yet