Vulnerability Description
grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
CVSS Score
5.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getgrav | Grav | < 1.7.22 |
Related Weaknesses (CWE)
References
- https://github.com/getgrav/grav/commit/c51fb1779b83f620c0b6f3548d4a96322b55df07Third Party Advisory
- https://huntr.dev/bounties/c2bc65af-7b93-4020-886e-8cdaeb0a58eaExploitPatchThird Party Advisory
- https://github.com/getgrav/grav/commit/c51fb1779b83f620c0b6f3548d4a96322b55df07Third Party Advisory
- https://huntr.dev/bounties/c2bc65af-7b93-4020-886e-8cdaeb0a58eaExploitPatchThird Party Advisory
FAQ
What is CVE-2021-3818?
CVE-2021-3818 is a vulnerability with a CVSS score of 5.3 (MEDIUM). grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
How severe is CVE-2021-3818?
CVE-2021-3818 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3818?
Check the references section above for vendor advisories and patch information. Affected products include: Getgrav Grav.