Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-474v-g7v9-75hp

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 7.5

Описание

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command execution.

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command execution.

EPSS

Процентиль: 51%
0.00276
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.8
nvd
23 дня назад

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command execution.

EPSS

Процентиль: 51%
0.00276
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-862