Логотип exploitDog
bind:CVE-2021-29440
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-29440

Количество 2

Количество 2

nvd логотип

CVE-2021-29440

почти 5 лет назад

Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. The issue was addressed in version 1.7.11.

CVSS3: 8.4
EPSS: Средний
github логотип

GHSA-g8r4-p96j-xfxc

почти 5 лет назад

Grav's Twig processing allowing dangerous PHP functions by default

CVSS3: 8.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-29440

Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. The issue was addressed in version 1.7.11.

CVSS3: 8.4
14%
Средний
почти 5 лет назад
github логотип
GHSA-g8r4-p96j-xfxc

Grav's Twig processing allowing dangerous PHP functions by default

CVSS3: 8.4
14%
Средний
почти 5 лет назад

Уязвимостей на страницу