GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command execution.
The attacker sends a crafted request to the scheduler endpoint, using the admin-nonce parameter to inject a payload encoded in base64. The vulnerability results from lack of access control (CWE-862) – the system does not verify the identity of the requester before processing the request. This makes it possible to overwrite YAML configuration and create malicious tasks (custom jobs) containing system commands, which are then executed by the server.
An attacker can gain remote code execution (RCE) with the permissions of the web server process, allowing complete system takeover, data theft, backdoor installation, or further lateral movement in the network.
Apply patches available from the vendor according to references (https://getgrav.org). Additionally, it is recommended to restrict network access to administrative endpoints (scheduler) at the firewall or reverse proxy level to trusted IP addresses.
GravCMS version 1.10.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XGetgrav Grav
APPGetgrav1.10.7
Related vulnerabilities
SSRF w Getgrav Grav przez szablony Twig — dostęp do zasobów wewnętrznych
XSS umożliwiający wykonanie kodu w Getgrav Grav (≤ 1.7.48)
Grav CMS: Server Side Template Injection umożliwia RCE
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.medi...
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the F...