CVE-2020-29553
15.03.2021, 19:15
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
Vendor | Product | Version |
---|---|---|
getgrav | grav_cms | 𝑥 ≤ 1.6.31 |
getgrav | grav_cms | 1.7.0:beta1 |
getgrav | grav_cms | 1.7.0:beta10 |
getgrav | grav_cms | 1.7.0:beta2 |
getgrav | grav_cms | 1.7.0:beta3 |
getgrav | grav_cms | 1.7.0:beta4 |
getgrav | grav_cms | 1.7.0:beta5 |
getgrav | grav_cms | 1.7.0:beta6 |
getgrav | grav_cms | 1.7.0:beta7 |
getgrav | grav_cms | 1.7.0:beta8 |
getgrav | grav_cms | 1.7.0:beta9 |
getgrav | grav_cms | 1.7.0:rc1 |
getgrav | grav_cms | 1.7.0:rc10 |
getgrav | grav_cms | 1.7.0:rc11 |
getgrav | grav_cms | 1.7.0:rc12 |
getgrav | grav_cms | 1.7.0:rc13 |
getgrav | grav_cms | 1.7.0:rc14 |
getgrav | grav_cms | 1.7.0:rc15 |
getgrav | grav_cms | 1.7.0:rc16 |
getgrav | grav_cms | 1.7.0:rc17 |
getgrav | grav_cms | 1.7.0:rc2 |
getgrav | grav_cms | 1.7.0:rc3 |
getgrav | grav_cms | 1.7.0:rc4 |
getgrav | grav_cms | 1.7.0:rc5 |
getgrav | grav_cms | 1.7.0:rc6 |
getgrav | grav_cms | 1.7.0:rc7 |
getgrav | grav_cms | 1.7.0:rc8 |
getgrav | grav_cms | 1.7.0:rc9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration