Aller au contenu principal
HIGH

CVE-2023-34253

CVSS v3

7.2

HIGH

Score EPSS

1.6 %

probabilité d’exploitation

CISA KEV

Non

exploitation connue

Exploitation

statut SSVC

Description

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using unsafe functions that are not banned, (2) using capitalised callable names, and (3) using fully-qualified names for referencing callables. Consequently, a low privileged attacker with login access to Grav Admin panel and page creation/update permissions is able to inject malicious templates to obtain remote code execution. A patch in version 1.7.42 improves the denylist.

Détails techniques

Publiée le
2023-06-14

Questions fréquentes

Qu’est-ce que CVE-2023-34253 ?

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using unsafe functions that are not banned, (2) using capitalised callable names, and (3) using fully-qualified names for referencing callables. Consequently, a low privileged attacker with login access to Grav Admin panel and page creation/update permissions is able to inject malicious templates to obtain remote code execution. A patch in version 1.7.42 improves the denylist.

CVE-2023-34253 est-elle activement exploitée ?

Aucune exploitation active de CVE-2023-34253 n’est confirmée. Le score EPSS est de 1.6 %, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2023-34253 ?

CVE-2023-34253 a un score de base CVSS v3 de 7.2 (gravité HIGH).

CVE-2023-34253 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite