Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8535-hvm8-2hmv

Опубликовано: 02 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.7

Описание

Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms

Summary

Having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload. Sensitive information may be contained in the configuration details.

PoC

Create a simple form with two fields, 'registration-number' and 'hp'. Add a submit button and set the method to POST(screenshot attached below). Form name set to 'hero-form'. Send a POST request with the following payload and you will notice a response with a php array listing the whole Grav configuration details - including plugins(screenshot attached).

registration-number:d643aaaa

hp:vJyifp

form-name:hero-form

unique_form_id:{{var_dump(_context|slice(0,7))}}

Screenshot 2025-03-25 at 7 26 02 AM

Screenshot 2025-03-25 at 7 22 58 AM

Impact

Server-Side Template (SST) vulnerability. The vulnerability affects the latest Grav version as of 25th of Match 2025 (1.7.48) with all plugins installed (including forms plugin v.7.4.2) to their latest versions as well.

Пакеты

Наименование

getgrav/grav

composer
Затронутые версииВерсия исправления

< 1.8.0-beta.27

1.8.0-beta.27

EPSS

Процентиль: 19%
0.0006
Низкий

7.7 High

CVSS4

Дефекты

CWE-1336

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side Template (SST) vulnerability. Sensitive information may be contained in the configuration details. This vulnerability is fixed in 1.8.0-beta.27.

EPSS

Процентиль: 19%
0.0006
Низкий

7.7 High

CVSS4

Дефекты

CWE-1336