PT-2021-18215 · Grav · Grav Admin Plugin

Published

2021-04-13

·

Updated

2023-11-06

·

CVE-2021-29439

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Grav admin plugin versions prior to 1.10.11
Description: The issue arises from incorrect verification of caller's privileges, allowing users with the admin.login permission to install third-party plugins and their dependencies. This can lead to arbitrary code execution and privilege elevation. Blocking access to the "/admin" path from untrusted sources can reduce the probability of exploitation.
Recommendations: For versions prior to 1.10.11, update to version 1.10.11 to address the issue. As a temporary workaround, consider blocking access to the "/admin" path from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-29439
GHSA-WG37-CF5X-55HQ

Affected Products

Grav Admin Plugin