CVE-2024-28116
HIGH 8.8EPSS 5.8%
Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authenticated user (editor permissions are sufficient) to execute arbitrary code on the remote server bypassing the existing security sandbox. Version 1.7.45 contains a patch for this issue.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 5.76% chance of exploitation in the next 30 days, 93th percentile
- Published
- 2024-03-21
- Updated
- 2024-08-02
Proof-of-concept exploits (4)
- getgrav/grav/security/advisories/GHSA-c9gp-64c4-2rrh
- advisories/GHSA-c9gp-64c4-2rrh
- akabe1/Graver8★ · 2024-03-24
- gunzf0x/Grav-CMS-RCE-Authenticated0★ · 2024-09-07