Looking for the vulnerability index of Invicti's legacy products?
Grav CMS Unauthenticated RCE (CVE-2021-21425) - Vulnerability Database

Grav CMS Unauthenticated RCE (CVE-2021-21425)

Description

Invicti has detected that the web application is based on Grav CMS. Grav Admin Plugin has a vulnerability that allows an unauthenticated user to execute some methods of administrator controller without needing any credentials. An attacker can use it to achieve RCE on the server.

Remediation

Upgrade to the latest version of Grav CMS

Related Vulnerabilities