Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
36Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 8.6epss 1.4%
da publicação à arma0 dias
Publicada no NVD1 de dez.
metasploit1 de dez.
probabilidade de exploração
1.4%top 31% das CVEs
exploração observada
nãonenhuma fonte reporta
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the form is now able to change the functioning of the form through modifying the content of the data[_json][header][form] which is the YAML frontmatter which includes the process section which dictates what happens after a user submits the form which include some important actions that could lead to further vulnerabilities. This vulnerability is fixed in 1.8.0-beta.27.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Produtos afetados
getgrav · grav