vendor:
Grav CMS
by:
enox
7.2
CVSS
HIGH
Server-Side Template Injection (SSTI)
94
CWE
Product Name: Grav CMS
Affected Version From: Grav CMS 1.7.10
Affected Version To: Grav CMS 1.7.10
Patch Exists: NO
Related CWE: CVE-2021-29440
CPE: a:grav_cms:grav_cms:1.7.10
Platforms Tested:
2021
Grav CMS 1.7.10 – Server-Side Template Injection (SSTI) (Authenticated)
This exploit allows an authenticated user to perform server-side template injection (SSTI) in Grav CMS 1.7.10. By creating a malicious page with a crafted template, an attacker can execute arbitrary code on the server.
Mitigation:
Upgrade to a patched version of Grav CMS.