Code Injection in Grav CMS - CVE-2024-28116
Published: March 22, 2024 / Updated: January 17, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to Server-Side Template Injection (SSTI) issue. A remote user can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2024-28116
Links to Public Exploits and PoC-codes
- Exploit #11070 - GenGravSSTIExploit (January 17, 2025)
- Exploit #10582 - GenGravSSTIExploit (October 11, 2024)
- Exploit #10569 - Grav-CMS-RCE-Authenticated (Exploit against Grav CMS (versions below 1.7.45) that allows Remote Code Execution for an authenticated user - CVE-2024-28116) (October 9, 2024)
- Exploit #9688 - Graver (April 9, 2024)