漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Grav Flex Objects - Server-Side Template Injection via Dynamic Titles
Vulnerability Description
The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or page.header.flex.object.title) to Twig's template_from_string(), causing them to be evaluated as Twig code rather than treated as text. This path bypasses Grav's Security::cleanDangerousTwig() sanitization. An attacker who can control the title frontmatter of a publicly reachable Flex Objects page can achieve arbitrary Twig execution and escalate to remote command execution via access to internal Grav services such as the scheduler.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
getgrav Grav 代码注入漏洞
Vulnerability Description
getgrav Grav是getgrav个人开发者开源的一套可扩展的内容管理系统。 getgrav Grav 1.4.0之前版本存在代码注入漏洞,该漏洞源于存储型服务器端模板注入问题。在渲染动态集合或对象标题时,该插件将用户控制的前置元数据值传递给Twig的template_from_string(),导致这些值被评估为Twig代码而不是作为文本处理,且绕过了Grav的Security::cleanDangerousTwig()清理。可能控制公开访问的Flex Objects页面标题前置元数据的攻击者能够
CVSS Information
N/A
Vulnerability Type
N/A