The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Grav_cms | Getgrav | * | 1.6.31 (including) |
Grav_cms | Getgrav | 1.7.0-beta1 (including) | 1.7.0-beta1 (including) |
Grav_cms | Getgrav | 1.7.0-beta10 (including) | 1.7.0-beta10 (including) |
Grav_cms | Getgrav | 1.7.0-beta2 (including) | 1.7.0-beta2 (including) |
Grav_cms | Getgrav | 1.7.0-beta3 (including) | 1.7.0-beta3 (including) |
Grav_cms | Getgrav | 1.7.0-beta4 (including) | 1.7.0-beta4 (including) |
Grav_cms | Getgrav | 1.7.0-beta5 (including) | 1.7.0-beta5 (including) |
Grav_cms | Getgrav | 1.7.0-beta6 (including) | 1.7.0-beta6 (including) |
Grav_cms | Getgrav | 1.7.0-beta7 (including) | 1.7.0-beta7 (including) |
Grav_cms | Getgrav | 1.7.0-beta8 (including) | 1.7.0-beta8 (including) |
Grav_cms | Getgrav | 1.7.0-beta9 (including) | 1.7.0-beta9 (including) |
Grav_cms | Getgrav | 1.7.0-rc1 (including) | 1.7.0-rc1 (including) |
Grav_cms | Getgrav | 1.7.0-rc10 (including) | 1.7.0-rc10 (including) |
Grav_cms | Getgrav | 1.7.0-rc11 (including) | 1.7.0-rc11 (including) |
Grav_cms | Getgrav | 1.7.0-rc12 (including) | 1.7.0-rc12 (including) |
Grav_cms | Getgrav | 1.7.0-rc13 (including) | 1.7.0-rc13 (including) |
Grav_cms | Getgrav | 1.7.0-rc14 (including) | 1.7.0-rc14 (including) |
Grav_cms | Getgrav | 1.7.0-rc15 (including) | 1.7.0-rc15 (including) |
Grav_cms | Getgrav | 1.7.0-rc16 (including) | 1.7.0-rc16 (including) |
Grav_cms | Getgrav | 1.7.0-rc17 (including) | 1.7.0-rc17 (including) |
Grav_cms | Getgrav | 1.7.0-rc2 (including) | 1.7.0-rc2 (including) |
Grav_cms | Getgrav | 1.7.0-rc3 (including) | 1.7.0-rc3 (including) |
Grav_cms | Getgrav | 1.7.0-rc4 (including) | 1.7.0-rc4 (including) |
Grav_cms | Getgrav | 1.7.0-rc5 (including) | 1.7.0-rc5 (including) |
Grav_cms | Getgrav | 1.7.0-rc6 (including) | 1.7.0-rc6 (including) |
Grav_cms | Getgrav | 1.7.0-rc7 (including) | 1.7.0-rc7 (including) |
Grav_cms | Getgrav | 1.7.0-rc8 (including) | 1.7.0-rc8 (including) |
Grav_cms | Getgrav | 1.7.0-rc9 (including) | 1.7.0-rc9 (including) |