Vulnerability CVE-2021-3818


Published: 2021-09-27

Description:
grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking

Type:

CWE-565

(Reliance on Cookies without Validation and Integrity Checking)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Getgrav -> GRAV 

 References:
https://github.com/getgrav/grav/commit/c51fb1779b83f620c0b6f3548d4a96322b55df07
https://huntr.dev/bounties/c2bc65af-7b93-4020-886e-8cdaeb0a58ea

Copyright 2024, cxsecurity.com

 

Back to Top