PT-2023-24775 · Twig+1 · Twig+1
Scgajge12
·
Publicado
2023-06-14
·
Atualizado
2023-06-22
·
CVE-2023-34251
CVSS v3.1
9.9
Crítica
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 1.7.42
Description
The issue allows for server-side template injection, which can lead to remote code execution. This can be achieved by embedding malicious PHP code on the administrator screen by a user with page editing privileges. The vulnerability exploits the
system function in the Twig template engine, allowing an attacker to execute arbitrary system commands.Recommendations
For Grav versions prior to 1.7.42, update to version 1.7.42 or later to resolve the issue. As a temporary workaround, consider restricting access to the administrator screen and the edit functionality for users with page editing privileges until the update can be applied.
Exploit
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Grav
Twig