Grav
cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*
- 1.7.49.5
A cross-site scripting (XSS) vulnerability has been identified in Grav CMS version 1.7.49.5. This issue allows remote attackers to inject arbitrary JavaScript, leading to stored XSS. The vulnerability arises because user input is returned without proper sanitization, enabling attackers to execute scripts in the context of the administrator's session.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
To reproduce this vulnerability, upload a parameter that includes JavaScript. The injected script will be executed when the page is accessed, demonstrating the cross-site scripting flaw.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.