CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2021-47812

CVSS 9.3v4.0pub. 2026-01-16upd. 2026-02-02

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command execution.

🤖 AI Analysis
How it works

The attacker sends a crafted request to the scheduler endpoint, using the admin-nonce parameter to inject a payload encoded in base64. The vulnerability results from lack of access control (CWE-862) – the system does not verify the identity of the requester before processing the request. This makes it possible to overwrite YAML configuration and create malicious tasks (custom jobs) containing system commands, which are then executed by the server.

Impact

An attacker can gain remote code execution (RCE) with the permissions of the web server process, allowing complete system takeover, data theft, backdoor installation, or further lateral movement in the network.

Mitigation & patch

Apply patches available from the vendor according to references (https://getgrav.org). Additionally, it is recommended to restrict network access to administrative endpoints (scheduler) at the firewall or reverse proxy level to trusted IP addresses.

Who is affected

GravCMS version 1.10.7

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Getgrav Grav

    APP
    Getgrav
    1.10.7
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-66844CRITICAL9.1PL ✓same product

SSRF w Getgrav Grav przez szablony Twig — dostęp do zasobów wewnętrznych

CVE-2025-46199CRITICAL9.8PL ✓same product

XSS umożliwiający wykonanie kodu w Getgrav Grav (≤ 1.7.48)

CVE-2023-34251CRITICAL9.9PL ✓same product

Grav CMS: Server Side Template Injection umożliwia RCE

CVE-2026-42844HIGH8.7same product

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.medi...

CVE-2026-42608HIGH8.8same product

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the F...