mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 17:50:34 +00:00
1.0 KiB
1.0 KiB
CVE-2024-27923
Description
Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the frontmatter
feature due to insufficient permission validation and inadequate file name validation. This may lead to remote code execution. Version 1.7.43 fixes this issue.
POC
Reference
- https://github.com/getgrav/grav/security/advisories/GHSA-f6g2-h7qv-3m5v
- https://github.com/getgrav/grav/security/advisories/GHSA-f6g2-h7qv-3m5v
Github
No PoCs found on GitHub currently.