← Back

CVE-2020-29553

nvd nist
Published: Mar 15, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).

Affected (28)

Products: Getgrav: Grav Cms
1 product
Grav Cms
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Getgrav
Up to 1.6.31
Version 1.7.0 beta10
Version 1.7.0 beta1
Version 1.7.0 beta2
Version 1.7.0 beta3
Version 1.7.0 beta4
Version 1.7.0 beta5
Version 1.7.0 beta6
Version 1.7.0 beta7
Version 1.7.0 beta8
Version 1.7.0 beta9
Version 1.7.0 rc10
Version 1.7.0 rc11
Version 1.7.0 rc12
Version 1.7.0 rc13
Version 1.7.0 rc14
Version 1.7.0 rc15
Version 1.7.0 rc16
Version 1.7.0 rc17
Version 1.7.0 rc1
Version 1.7.0 rc2
Version 1.7.0 rc3
Version 1.7.0 rc4
Version 1.7.0 rc5
Version 1.7.0 rc6
Version 1.7.0 rc7
Version 1.7.0 rc8
Version 1.7.0 rc9

Timeline

No history available yet.