SB2020121038 - Cross-site scripting in Grav CMS
Published: December 10, 2020 Updated: May 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cross-site scripting (CVE-ID: N/A)
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in the Admin plugin page editor when editing pages with the default security configuration. A remote user can inject a crafted script to execute arbitrary code.
Exploitation requires the ability to edit pages and can lead to execution of functionality on behalf of a stolen administrative account, which may then be used to install a custom plugin containing a web shell.
Remediation
Install update from vendor's website.