In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
The vulnerability is triggered through Twig templates during page content processing when the application configuration allows registration of undefined PHP functions. An attacker can craft appropriate code in a Twig template that will cause the server to execute an HTTP request to internal or external network resources. No authentication or user interaction is required, meaning the exploit can be carried out remotely over the network.
An attacker can gain access to sensitive internal network infrastructure resources and manipulate network traffic generated by the server, which may lead to disclosure of sensitive data and system integrity violation.
Grav should be updated to version 1.7.49.5 or later. Additionally, it is recommended to verify the application configuration to restrict the possibility of registering undefined PHP functions in Twig templates.
Getgrav Grav in versions below 1.7.49.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NGetgrav Grav
APPGetgrav< 1.7.49.5
Related vulnerabilities
GravCMS – nieuwierzytelniony zapis YAML i zdalne wykonanie kodu PHP
XSS umożliwiający wykonanie kodu w Getgrav Grav (≤ 1.7.48)
Grav CMS: Server Side Template Injection umożliwia RCE
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.medi...
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the F...