First published: Mon Mar 15 2021(Updated: )
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getgrav Grav Cms | <=1.6.31 | |
Getgrav Grav Cms | =1.7.0-beta1 | |
Getgrav Grav Cms | =1.7.0-beta10 | |
Getgrav Grav Cms | =1.7.0-beta2 | |
Getgrav Grav Cms | =1.7.0-beta3 | |
Getgrav Grav Cms | =1.7.0-beta4 | |
Getgrav Grav Cms | =1.7.0-beta5 | |
Getgrav Grav Cms | =1.7.0-beta6 | |
Getgrav Grav Cms | =1.7.0-beta7 | |
Getgrav Grav Cms | =1.7.0-beta8 | |
Getgrav Grav Cms | =1.7.0-beta9 | |
Getgrav Grav Cms | =1.7.0-rc1 | |
Getgrav Grav Cms | =1.7.0-rc10 | |
Getgrav Grav Cms | =1.7.0-rc11 | |
Getgrav Grav Cms | =1.7.0-rc12 | |
Getgrav Grav Cms | =1.7.0-rc13 | |
Getgrav Grav Cms | =1.7.0-rc14 | |
Getgrav Grav Cms | =1.7.0-rc15 | |
Getgrav Grav Cms | =1.7.0-rc16 | |
Getgrav Grav Cms | =1.7.0-rc17 | |
Getgrav Grav Cms | =1.7.0-rc2 | |
Getgrav Grav Cms | =1.7.0-rc3 | |
Getgrav Grav Cms | =1.7.0-rc4 | |
Getgrav Grav Cms | =1.7.0-rc5 | |
Getgrav Grav Cms | =1.7.0-rc6 | |
Getgrav Grav Cms | =1.7.0-rc7 | |
Getgrav Grav Cms | =1.7.0-rc8 | |
Getgrav Grav Cms | =1.7.0-rc9 | |
composer/getgrav/grav | <1.6.30 | 1.6.30 |
composer/getgrav/grav | >=1.7.0-beta.1<=1.7.0-rc.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29553 is a vulnerability in the scheduler of Grav CMS through 1.7.0-rc.17 that allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
CVE-2020-29553 has a severity score of 8.8 (high).
Grav CMS versions 1.6.31 and 1.7.0-beta1 to 1.7.0-rc17 are affected by CVE-2020-29553.
To fix the CVE-2020-29553 vulnerability, users should update Grav CMS to version 1.7.1 or later.
You can find more information about CVE-2020-29553 at this reference: https://blog.bssi.fr/cve-2020-29553-cve-2020-29555-cve-2020-29556-multiple-vulnerabilities-within-cms-grav/