Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36212
HistoryJun 30, 2022 - 5:21 a.m.

Remote Code Execution

2022-06-3005:21:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
30
getgrav/grav
remote code execution
twig template injection
server side
authenticated remote attacker
risky functions
system
software

EPSS

0.001

Percentile

41.2%

getgrav/grav is vulnerable to remote code execution. An authenticated remote attacker is able to cause server side template injection via Twig which renders risky functions by default, such as system.

EPSS

0.001

Percentile

41.2%