PT-2021-14497 · Grav · Grav Admin Plugin

Mehmet Ince

·

Published

2021-04-07

·

Updated

2022-10-24

·

CVE-2021-21425

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav Admin Plugin versions 1.10.7 and earlier
Description The issue allows an unauthenticated user to execute certain methods of the administrator controller without credentials, resulting in arbitrary YAML file creation or modification. This can lead to configuration changes, such as altering site information or scheduler jobs. An adversary can exploit this to change parts of the webpage, hijack an administrator account, or execute operating system commands under the web-server user context.
Recommendations For versions 1.10.7 and earlier, update to version 1.10.8 to resolve the issue. As a temporary workaround, consider blocking access to the "/admin" path from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2021-21425
GHSA-6F53-6QGV-39PJ

Affected Products

Grav Admin Plugin