Vulnerability Database

300,445

Total vulnerabilities in the database

CVE-2020-29553

The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).

  • Published: Mar 15, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2020-29553
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.8
  • AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 5.1
  • AV:N/AC:H/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
getgrav / grav_cms 1.7.0-beta8 1.7.0-beta8.x
getgrav / grav_cms 1.7.0-beta9 1.7.0-beta9.x
getgrav / grav_cms 1.7.0-beta10 1.7.0-beta10.x
getgrav / grav_cms 1.7.0-rc1 1.7.0-rc1.x
getgrav / grav_cms 1.7.0-rc2 1.7.0-rc2.x
getgrav / grav_cms 1.7.0-rc3 1.7.0-rc3.x
getgrav / grav_cms 1.7.0-rc4 1.7.0-rc4.x
getgrav / grav_cms 1.7.0-rc5 1.7.0-rc5.x
getgrav / grav_cms 1.7.0-rc6 1.7.0-rc6.x
getgrav / grav_cms 1.7.0-rc7 1.7.0-rc7.x
getgrav / grav_cms 1.7.0-rc8 1.7.0-rc8.x
getgrav / grav_cms 1.7.0-rc9 1.7.0-rc9.x
getgrav / grav_cms 1.7.0-rc10 1.7.0-rc10.x
getgrav / grav_cms 1.7.0-rc11 1.7.0-rc11.x
getgrav / grav_cms 1.7.0-rc12 1.7.0-rc12.x
getgrav / grav_cms 1.7.0-rc13 1.7.0-rc13.x
getgrav / grav_cms 1.7.0-rc14 1.7.0-rc14.x
getgrav / grav_cms 1.7.0-rc15 1.7.0-rc15.x
getgrav / grav_cms 1.7.0-rc16 1.7.0-rc16.x
getgrav / grav_cms 1.7.0-rc17 1.7.0-rc17.x
getgrav / grav_cms 1.7.0-beta1 1.7.0-beta1.x
getgrav / grav_cms 1.7.0-beta2 1.7.0-beta2.x
getgrav / grav_cms 1.7.0-beta3 1.7.0-beta3.x
getgrav / grav_cms 1.7.0-beta4 1.7.0-beta4.x
getgrav / grav_cms 1.7.0-beta5 1.7.0-beta5.x
getgrav / grav_cms 1.7.0-beta6 1.7.0-beta6.x
getgrav / grav_cms 1.7.0-beta7 1.7.0-beta7.x
getgrav / grav_cms - 1.6.31.x