Логотип exploitDog
bind:CVE-2023-34253
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-34253

Количество 2

Количество 2

nvd логотип

CVE-2023-34253

больше 2 лет назад

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using unsafe functions that are not banned, (2) using capitalised callable names, and (3) using fully-qualified names for referencing callables. Consequently, a low privileged attacker with login access to Grav Admin panel and page creation/update permissions is able to inject malicious templates to obtain remote code execution. A patch in version 1.7.42 improves the denylist.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-j3v8-v77f-fvgm

больше 2 лет назад

Grav Server-side Template Injection (SSTI) via Denylist Bypass Vulnerability

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-34253

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using unsafe functions that are not banned, (2) using capitalised callable names, and (3) using fully-qualified names for referencing callables. Consequently, a low privileged attacker with login access to Grav Admin panel and page creation/update permissions is able to inject malicious templates to obtain remote code execution. A patch in version 1.7.42 improves the denylist.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-j3v8-v77f-fvgm

Grav Server-side Template Injection (SSTI) via Denylist Bypass Vulnerability

CVSS3: 7.2
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу