PT-2023-24775 · Twig+1 · Twig+1

Scgajge12

·

Publicado

2023-06-14

·

Atualizado

2023-06-22

·

CVE-2023-34251

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.7.42
Description The issue allows for server-side template injection, which can lead to remote code execution. This can be achieved by embedding malicious PHP code on the administrator screen by a user with page editing privileges. The vulnerability exploits the system function in the Twig template engine, allowing an attacker to execute arbitrary system commands.
Recommendations For Grav versions prior to 1.7.42, update to version 1.7.42 or later to resolve the issue. As a temporary workaround, consider restricting access to the administrator screen and the edit functionality for users with page editing privileges until the update can be applied.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-34251
GHSA-F9JF-4CP4-4FQ5

Produtos afetados

Grav
Twig