CVE-2020-19625

CRITICAL EXPLOITED NUCLEI

gridx 1.3 - Remote Code Execution via $query Parameter in test_grid_filter.php

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-19625 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.

Nuclei Templates (1)

Gridx 1.3 - Remote Code Execution
CRITICALby geeknik

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/oria/gridx/issues/433

Scores

CVSS v3 9.8
EPSS 0.1314
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-27
Status published
Products (1)
gridx_project/gridx 1.3
Published Mar 26, 2021
Tracked Since Feb 18, 2026