CVE-2021-29440

HIGH

Grav < 1.7.11 - Code Injection

Title source: rule

Description

Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. The issue was addressed in version 1.7.11.

Exploits (2)

exploitdb WORKING POC
by enox · pythonwebappsphp
https://www.exploit-db.com/exploits/49961
nomisec WORKING POC 4 stars
by CsEnox · poc
https://github.com/CsEnox/CVE-2021-29440

Scores

CVSS v3 8.4
EPSS 0.1116
EPSS Percentile 93.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (2)
getgrav/grav < 1.7.11
getgrav/grav 0 - 1.7.11Packagist
Published Apr 13, 2021
Tracked Since Feb 18, 2026