First published: Mon Mar 19 2018(Updated: )
Cross-site scripting (XSS) vulnerability in `system/src/Grav/Common/Twig/Twig.php` in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getgrav Grav Cms | <1.3.0 | |
composer/getgrav/grav | <1.3.0 | 1.3.0 |
<1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5233 is a Cross-site scripting (XSS) vulnerability in Grav CMS before version 1.3.0.
CVE-2018-5233 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.
CVE-2018-5233 has a severity rating of 6.1 (medium).
To fix CVE-2018-5233, you should update Grav CMS to version 1.3.0 or higher.
You can find more information about CVE-2018-5233 at the following references: - [http://www.openwall.com/lists/oss-security/2018/03/15/1](http://www.openwall.com/lists/oss-security/2018/03/15/1) - [https://sysdream.com/news/lab/2018-03-15-cve-2018-5233-grav-cms-admin-plugin-reflected-cross-site-scripting-xss-vulnerability/](https://sysdream.com/news/lab/2018-03-15-cve-2018-5233-grav-cms-admin-plugin-reflected-cross-site-scripting-xss-vulnerability/)