CVE-2020-29553: CSRF
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29553?
CVE-2020-29553 is a vulnerability in the scheduler of Grav CMS through 1.7.0-rc.17 that allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
How severe is CVE-2020-29553?
CVE-2020-29553 has a severity score of 8.8 (high).
What software is affected by CVE-2020-29553?
Grav CMS versions 1.6.31 and 1.7.0-beta1 to 1.7.0-rc17 are affected by CVE-2020-29553.
How can the CVE-2020-29553 vulnerability be fixed?
To fix the CVE-2020-29553 vulnerability, users should update Grav CMS to version 1.7.1 or later.
Where can I find more information about CVE-2020-29553?
You can find more information about CVE-2020-29553 at this reference: https://blog.bssi.fr/cve-2020-29553-cve-2020-29555-cve-2020-29556-multiple-vulnerabilities-within-cms-grav/