PT-2021-14497 · Grav · Grav Admin Plugin
Mehmet Ince
·
Published
2021-04-07
·
Updated
2022-10-24
·
CVE-2021-21425
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav Admin Plugin versions 1.10.7 and earlier
Description
The issue allows an unauthenticated user to execute certain methods of the administrator controller without credentials, resulting in arbitrary YAML file creation or modification. This can lead to configuration changes, such as altering site information or scheduler jobs. An adversary can exploit this to change parts of the webpage, hijack an administrator account, or execute operating system commands under the web-server user context.
Recommendations
For versions 1.10.7 and earlier, update to version 1.10.8 to resolve the issue.
As a temporary workaround, consider blocking access to the "/admin" path from untrusted sources to minimize the risk of exploitation.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav Admin Plugin