Описание
Code injection in grav
Grav is vulnerable to Server Side Template Injection via Twig. According to a previous vulnerability report, Twig should not render dangerous functions by default, such as system.
Пакеты
Наименование
getgrav/grav
composer
Затронутые версииВерсия исправления
< 1.7.34
1.7.34
Связанные уязвимости
CVSS3: 7.2
nvd
больше 3 лет назад
Code Injection in GitHub repository getgrav/grav prior to 1.7.34.