PT-2026-3182 · Grav Cms · Grav Cms

Legend

·

Published

2026-01-15

·

Updated

2026-01-16

·

CVE-2021-47812

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GravCMS version 1.10.7
Description GravCMS version 1.10.7 has an issue allowing remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command execution. The ''/scheduler'' endpoint is affected. The admin-nonce parameter is used to inject payloads.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-47812

Affected Products

Grav Cms