CVE-2020-19625
CRITICAL EXPLOITED NUCLEIgridx 1.3 - Remote Code Execution via $query Parameter in test_grid_filter.php
Title source: llmExploitation Summary
CVE-2020-19625 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.
Nuclei Templates (1)
Gridx 1.3 - Remote Code Execution
CRITICALby geeknik
References (2)
Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/oria/gridx/issues/433
Exploit, Third Party Advisory x_refsource_misc
http://mayoterry.com/file/cve/Remote_Code_Execution_Vulnerability_in_gridx_latest_version.pdf
Scores
CVSS v3
9.8
EPSS
0.1314
EPSS Percentile
95.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2023-11-27
Status
published
Products (1)
gridx_project/gridx
1.3
Published
Mar 26, 2021
Tracked Since
Feb 18, 2026