VYPR
High severity8.8NVD Advisory· Published Mar 21, 2024· Updated Jun 17, 2026

CVE-2024-28116

CVE-2024-28116

Description

Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authenticated user (editor permissions are sufficient) to execute arbitrary code on the remote server bypassing the existing security sandbox. Version 1.7.45 contains a patch for this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
getgrav/gravPackagist
< 1.7.451.7.45

Affected products

3
  • Getgrav/Grav2 versions
    cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*range: <1.7.45
    • (no CPE)range: < 1.7.45
  • ghsa-coords
    Range: < 1.7.45

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.