CVE-2020-29553

The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
getgravgrav_cms
𝑥
≤ 1.6.31
getgravgrav_cms
1.7.0:beta1
getgravgrav_cms
1.7.0:beta10
getgravgrav_cms
1.7.0:beta2
getgravgrav_cms
1.7.0:beta3
getgravgrav_cms
1.7.0:beta4
getgravgrav_cms
1.7.0:beta5
getgravgrav_cms
1.7.0:beta6
getgravgrav_cms
1.7.0:beta7
getgravgrav_cms
1.7.0:beta8
getgravgrav_cms
1.7.0:beta9
getgravgrav_cms
1.7.0:rc1
getgravgrav_cms
1.7.0:rc10
getgravgrav_cms
1.7.0:rc11
getgravgrav_cms
1.7.0:rc12
getgravgrav_cms
1.7.0:rc13
getgravgrav_cms
1.7.0:rc14
getgravgrav_cms
1.7.0:rc15
getgravgrav_cms
1.7.0:rc16
getgravgrav_cms
1.7.0:rc17
getgravgrav_cms
1.7.0:rc2
getgravgrav_cms
1.7.0:rc3
getgravgrav_cms
1.7.0:rc4
getgravgrav_cms
1.7.0:rc5
getgravgrav_cms
1.7.0:rc6
getgravgrav_cms
1.7.0:rc7
getgravgrav_cms
1.7.0:rc8
getgravgrav_cms
1.7.0:rc9
𝑥
= Vulnerable software versions