7.2
CVSSv3

CVE-2023-34251

Published: 14/06/2023 Updated: 22/06/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Grav is a flat-file content management system. Versions before 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains a fix for this issue.

Vulnerable Product Search on Vulmon Subscribe to Product

getgrav grav