SB2023071878 - Return of Wrong Status Code in Grav CMS



SB2023071878 - Return of Wrong Status Code in Grav CMS

Published: July 18, 2023 Updated: May 5, 2026

Security Bulletin ID SB2023071878
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Return of Wrong Status Code (CVE-ID: CVE-2023-37897)

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to return of wrong status code in isDangerousFunction() when processing Twig |map input containing a double backslash. A remote privileged user can submit a specially crafted Twig payload to execute arbitrary code.

Exploitation requires access to the Admin panel with page create or update permissions and Twig processing enabled for the modified page.


Remediation

Install update from vendor's website.