vendor:
GravCMS
by:
Mehmet Ince
8.8
CVSS
HIGH
Arbitrary YAML Write/Update
20
CWE
Product Name: GravCMS
Affected Version From: 1.10.7
Affected Version To: 1.10.7
Patch Exists: YES
Related CWE: N/A
CPE: a:getgrav:grav:1.10.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian 10
2020
GravCMS 1.10.7 – Arbitrary YAML Write/Update (Unauthenticated) (2)
An unauthenticated attacker can exploit a vulnerability in GravCMS 1.10.7 to execute arbitrary YAML write/update. The vulnerability exists due to insufficient validation of user-supplied input in the 'admin/tools/scheduler' endpoint. An attacker can send a specially crafted request to the endpoint to execute arbitrary YAML write/update. This can allow the attacker to execute arbitrary code on the vulnerable system.
Mitigation:
Upgrade to the latest version of GravCMS.