CVE-2018-5233: XSS
Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATHINFO to admin/tools.
Other sources
Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATHINFO to admin/tools.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5233?
CVE-2018-5233 is a Cross-site scripting (XSS) vulnerability in Grav CMS before version 1.3.0.
How does CVE-2018-5233 affect Grav CMS?
CVE-2018-5233 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.
What is the severity of CVE-2018-5233?
CVE-2018-5233 has a severity rating of 6.1 (medium).
How can I fix CVE-2018-5233?
To fix CVE-2018-5233, you should update Grav CMS to version 1.3.0 or higher.
Where can I find more information about CVE-2018-5233?
You can find more information about CVE-2018-5233 at the following references: - [http://www.openwall.com/lists/oss-security/2018/03/15/1](http://www.openwall.com/lists/oss-security/2018/03/15/1) - [https://sysdream.com/news/lab/2018-03-15-cve-2018-5233-grav-cms-admin-plugin-reflected-cross-site-scripting-xss-vulnerability/](https://sysdream.com/news/lab/2018-03-15-cve-2018-5233-grav-cms-admin-plugin-reflected-cross-site-scripting-xss-vulnerability/)