Tag
high
advisory
Grav File Cache Insecure Deserialization Vulnerability
2 rules 2 TTPsGrav versions 1.7.44 through 1.7.49.5 are vulnerable to insecure deserialization in the File Cache component, where the `unserialize` function with `allowed_classes => true` can lead to arbitrary code execution if an attacker tampers with cache files.
grav
insecure-deserialization
code-execution
web-application
2r
2t
critical
advisory
Grav Login Plugin Privilege Escalation Vulnerability
2 rules 1 TTP 1 IOCUnauthenticated users can escalate privileges to admin in Grav CMS by manipulating registration data due to missing server-side validation in the Login plugin.
Login Plugin +2
grav
privilege-escalation
web
2r
1t
1i
high
advisory
Grav API Plugin Privilege Escalation Vulnerability
2 rules 1 TTPA privilege escalation vulnerability in the Grav API plugin allows authenticated users with basic API access to elevate their privileges to Super Administrator, leading to full system compromise and potential remote code execution.
grav-plugin-api
privilege-escalation
web-application
grav
2r
1t