CVE-2020-36955
EUVD-2020-3084726.01.2026, 18:16
Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.
Awaiting analysis
This vulnerability is currently awaiting analysis.