CVE-2023-34253: Grav vulnerable to Server-side Template Injection (SSTI) via Denylist Bypass

Published Jun 14, 2023
·
Updated

Grav is a file-based Web platform. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using unsafe functions that are not banned, (2) using capitalised callable names, and (3) using fully-qualified names for referencing callables. Consequently, a low privileged attacker with login access to Grav Admin panel and page creation/update permissions is able to inject malicious templates to obtain remote code execution. A patch in version 1.7.42 improves the denylist.

Other sources

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using unsafe functions that are not banned, (2) using capitalised callable names, and (3) using fully-qualified names for referencing callables. Consequently, a low privileged attacker with login access to Grav Admin panel and page creation/update permissions is able to inject malicious templates to obtain remote code execution. A patch in version 1.7.42 improves the denylist.

MITRE

Affected Software

1 affected component
getgrav Grav<1.7.42

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade grav to a version that resolves this vulnerability.

    Fixed in 1.7.42Patch 9d6a2d
  2. Operational

    If a low-privileged attacker was able to create/update pages in the Grav Admin panel before upgrading to 1.7.42, review and remove any malicious templates that may have been injected and restore affected content.

Event History

Jun 14, 2023
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2023-34253?

CVE-2023-34253 is a vulnerability in Grav, a file-based Web platform, where the denylist introduced in version 1.7.42 can be easily subverted, allowing the execution of dangerous functions via injection of malicious templates.

2

What is the severity of CVE-2023-34253?

CVE-2023-34253 has a severity level of 7.2, which is categorized as high.

3

How does CVE-2023-34253 affect Grav?

CVE-2023-34253 affects Grav versions up to and excluding 1.7.42. The denylist feature introduced in prior versions can be bypassed, making it possible to execute dangerous functions through injection of malicious templates.

4

How can I fix CVE-2023-34253 in Grav?

To fix CVE-2023-34253 in Grav, it is recommended to update to version 1.7.42 or later, which includes the necessary fixes for the vulnerability.

5

Where can I find more information about CVE-2023-34253?

For more information about CVE-2023-34253, you can refer to the following resources: [GitHub commit](https://github.com/getgrav/grav/commit/71bbed12f950de8335006d7f91112263d8504f1b), [Grav security advisory](https://github.com/getgrav/grav/security/advisories/GHSA-j3v8-v77f-fvgm).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203