CVE-2020-36955
MEDIUMGrav CMS 1.6.30 with Admin Plugin 1.9.18 - Authenticated Stored Cross-Site Scripting via Page Title Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36955. PoCs published by Sagar Banwa.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Grav CMS Admin Plugin by injecting a malicious script into the 'Page Title' field, which executes when the page is viewed or listed.
Description
Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Grav CMS Admin Plugin by injecting a malicious script into the 'Page Title' field, which executes when the page is viewed or listed.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N