CVE-2023-34253
HIGHGrav < 1.7.42 - Authenticated Remote Code Execution via Template Injection Denylist Bypass
Title source: llmDescription
Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using unsafe functions that are not banned, (2) using capitalised callable names, and (3) using fully-qualified names for referencing callables. Consequently, a low privileged attacker with login access to Grav Admin panel and page creation/update permissions is able to inject malicious templates to obtain remote code execution. A patch in version 1.7.42 improves the denylist.
References (5)
Core 5
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/getgrav/grav/security/advisories/GHSA-j3v8-v77f-fvgm
Patch x_refsource_misc
https://github.com/getgrav/grav/commit/71bbed12f950de8335006d7f91112263d8504f1b
Issue Tracking x_refsource_misc
https://github.com/getgrav/grav/blob/1.7.40/system/src/Grav/Common/Utils.php#L1952-L2190
Exploit, Third Party Advisory x_refsource_misc
https://huntr.dev/bounties/3ef640e6-9e25-4ecb-8ec1-64311d63fe66/
Patch x_refsource_misc
https://www.github.com/getgrav/grav/commit/9d6a2dba09fd4e56f5cdfb9a399caea355bfeb83
Scores
CVSS v3
8.8
EPSS
0.0206
EPSS Percentile
78.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-184
CWE-1336
CWE-94
Status
published
Products (2)
getgrav/grav
< 1.7.42
getgrav/grav
0 - 1.7.42Packagist
Published
Jun 14, 2023
Tracked Since
Feb 18, 2026