mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-31 18:50:38 +00:00
20 lines
1.0 KiB
Markdown
20 lines
1.0 KiB
Markdown
### [CVE-2024-27923](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27923)
|
|

|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient permission validation and inadequate file name validation. This may lead to remote code execution. Version 1.7.43 fixes this issue.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/getgrav/grav/security/advisories/GHSA-f6g2-h7qv-3m5v
|
|
- https://github.com/getgrav/grav/security/advisories/GHSA-f6g2-h7qv-3m5v
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|