CVE-2023-34251

high

Description

Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains a fix for this issue.

References

https://github.com/getgrav/grav/security/advisories/GHSA-f9jf-4cp4-4fq5

https://github.com/getgrav/grav/commit/9d01140a63c77075ef09b26ef57cf186138151a5

https://github.com/getgrav/grav/blob/develop/system/src/Grav/Common/Twig/Extension/GravExtension.php#L174

Details

Source: Mitre, NVD

Published: 2023-06-14

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.05288