CVE-2020-36955: Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting
Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36955?
CVE-2020-36955 is classified as a medium severity vulnerability due to the potential for authenticated attackers to exploit it.
How do I fix CVE-2020-36955?
To fix CVE-2020-36955, update Grav CMS and the Admin Plugin to their latest versions to eliminate the persistent cross-site scripting vulnerability.
Who is affected by CVE-2020-36955?
CVE-2020-36955 affects users of Grav CMS version 1.6.30 with the Admin Plugin version 1.9.18.
What type of vulnerability is CVE-2020-36955?
CVE-2020-36955 is a persistent cross-site scripting (XSS) vulnerability that allows script injection through the page title field.
What can attackers do with CVE-2020-36955?
Attackers can exploit CVE-2020-36955 to inject malicious scripts that may execute in the context of authenticated users, potentially leading to data theft or other malicious activities.