Vendor
high
advisory
Grav File Cache Insecure Deserialization Vulnerability
2 rules 2 TTPsGrav versions 1.7.44 through 1.7.49.5 are vulnerable to insecure deserialization in the File Cache component, where the `unserialize` function with `allowed_classes => true` can lead to arbitrary code execution if an attacker tampers with cache files.
grav
insecure-deserialization
code-execution
web-application
2r
2t
high
advisory
Grav API Plugin Privilege Escalation Vulnerability
2 rules 1 TTPA privilege escalation vulnerability in the Grav API plugin allows authenticated users with basic API access to elevate their privileges to Super Administrator, leading to full system compromise and potential remote code execution.
grav-plugin-api
privilege-escalation
web-application
grav
2r
1t