8.8

CVE-2020-29553

Exploit
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GetgravGrav Cms Version <= 1.6.31
GetgravGrav Cms Version1.7.0 Updatebeta1
GetgravGrav Cms Version1.7.0 Updatebeta10
GetgravGrav Cms Version1.7.0 Updatebeta2
GetgravGrav Cms Version1.7.0 Updatebeta3
GetgravGrav Cms Version1.7.0 Updatebeta4
GetgravGrav Cms Version1.7.0 Updatebeta5
GetgravGrav Cms Version1.7.0 Updatebeta6
GetgravGrav Cms Version1.7.0 Updatebeta7
GetgravGrav Cms Version1.7.0 Updatebeta8
GetgravGrav Cms Version1.7.0 Updatebeta9
GetgravGrav Cms Version1.7.0 Updaterc1
GetgravGrav Cms Version1.7.0 Updaterc10
GetgravGrav Cms Version1.7.0 Updaterc11
GetgravGrav Cms Version1.7.0 Updaterc12
GetgravGrav Cms Version1.7.0 Updaterc13
GetgravGrav Cms Version1.7.0 Updaterc14
GetgravGrav Cms Version1.7.0 Updaterc15
GetgravGrav Cms Version1.7.0 Updaterc16
GetgravGrav Cms Version1.7.0 Updaterc17
GetgravGrav Cms Version1.7.0 Updaterc2
GetgravGrav Cms Version1.7.0 Updaterc3
GetgravGrav Cms Version1.7.0 Updaterc4
GetgravGrav Cms Version1.7.0 Updaterc5
GetgravGrav Cms Version1.7.0 Updaterc6
GetgravGrav Cms Version1.7.0 Updaterc7
GetgravGrav Cms Version1.7.0 Updaterc8
GetgravGrav Cms Version1.7.0 Updaterc9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.325
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.