CVE-2020-37256: Grav - Cross-Site Scripting in Admin Plugin Page Editor
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Gravto a version that resolves this vulnerability.Fixed in 1.6.30 - Compensating control
Limit page-editing capabilities to trusted privileged users only (users with Admin plugin page editor access) to reduce risk of malicious script injection and plugin installation.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37256?
CVE-2020-37256 has a severity rating of medium, with a score of 5.1.
What kind of vulnerability is CVE-2020-37256?
CVE-2020-37256 is a cross-site scripting (XSS) vulnerability affecting the Admin plugin page editor in Grav.
How does CVE-2020-37256 impact users?
CVE-2020-37256 allows privileged users to inject malicious scripts, potentially leading to arbitrary code execution.
How do I fix CVE-2020-37256?
To fix CVE-2020-37256, upgrade Grav to version 1.6.30 or later.
Who is affected by CVE-2020-37256?
CVE-2020-37256 affects users with page editing capabilities in Grav's Admin plugin.