Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields
An attacker introduces specially crafted scripts into form fields available in the Grav application. The lack of proper validation or sanitization of input data causes malicious code to be stored or reflected and then executed in the context of the victim's browser. This mechanism is classified as CWE-79 (improper neutralization of input during web page generation).
An attacker can execute arbitrary JavaScript code in the victim's browser session, which may lead to account takeover, theft of authentication credentials, and further compromise of system confidentiality, integrity, and availability.
Grav should be updated to a version higher than 1.7.48. Patches available from the vendor should be applied according to the references. Additionally, it is recommended to verify and strengthen validation of input data in form fields.
Getgrav Grav version 1.7.48 and all earlier versions
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGetgrav Grav
APPGetgrav≤ 1.7.48
Related vulnerabilities
GravCMS – nieuwierzytelniony zapis YAML i zdalne wykonanie kodu PHP
SSRF w Getgrav Grav przez szablony Twig — dostęp do zasobów wewnętrznych
Grav CMS: Server Side Template Injection umożliwia RCE
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.medi...
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the F...