ID:6468 - Exploit for Improper access control in Grav Admin Plugin - CVE-2021-21425
Published: June 24, 2021
Grav Admin Plugin
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can execute some methods of administrator controller without needing any credentials, leading to arbitrary YAML file creation or content change of existing YAML files on the system.