Vulnerability Description
Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://getgrav.org/
- https://www.exploit-db.com/exploits/49264
- https://www.vulncheck.com/advisories/grav-cms-admin-plugin-page-title-persistent
FAQ
What is CVE-2020-36955?
CVE-2020-36955 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attacker...
How severe is CVE-2020-36955?
CVE-2020-36955 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36955?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.