Lucene search

K
osvGoogleOSV:GHSA-FQFF-VCVX-68H3
HistoryMay 24, 2022 - 5:44 p.m.

Grav CMS Cross-Site Request Forgery (CSRF)

2022-05-2417:44:32
Google
osv.dev
4

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.2%

The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.2%

Related for OSV:GHSA-FQFF-VCVX-68H3