Description
GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command execution.
Problem types
Product status
Credits
legend
References
www.exploit-db.com/exploits/49973
www.exploit-db.com/exploits/49973 (ExploitDB-49973)
getgrav.org (Official Grav CMS Homepage)
www.vulncheck.com/...itrary-yaml-writeupdate-unauthenticated (VulnCheck Advisory: GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2))