CRITICAL🇵🇱 Wersja polska

CVE-2025-46199

CVSS 9.8v3.1pub. 2025-07-25upd. 2025-08-15

Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields

🤖 AI Analysis
How it works

An attacker introduces specially crafted scripts into form fields available in the Grav application. The lack of proper validation or sanitization of input data causes malicious code to be stored or reflected and then executed in the context of the victim's browser. This mechanism is classified as CWE-79 (improper neutralization of input during web page generation).

Impact

An attacker can execute arbitrary JavaScript code in the victim's browser session, which may lead to account takeover, theft of authentication credentials, and further compromise of system confidentiality, integrity, and availability.

Mitigation & patch

Grav should be updated to a version higher than 1.7.48. Patches available from the vendor should be applied according to the references. Additionally, it is recommended to verify and strengthen validation of input data in form fields.

Who is affected

Getgrav Grav version 1.7.48 and all earlier versions

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Getgrav Grav

    APP
    Getgrav
    ≤ 1.7.48
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2021-47812CRITICAL9.3PL ✓same product

GravCMS – nieuwierzytelniony zapis YAML i zdalne wykonanie kodu PHP

CVE-2025-66844CRITICAL9.1PL ✓same product

SSRF w Getgrav Grav przez szablony Twig — dostęp do zasobów wewnętrznych

CVE-2023-34251CRITICAL9.9PL ✓same product

Grav CMS: Server Side Template Injection umożliwia RCE

CVE-2026-42844HIGH8.7same product

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.medi...

CVE-2026-42608HIGH8.8same product

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the F...