CVE-2023-37897 is a high-severity Server-Side Template Injection (SSTI) vulnerability affecting Grav, a PHP-based web platform. This flaw allows authenticated attackers (administrators or non-admin users with specific permissions) to execute arbitrary code due to an incorrect denylist bypass in a previous security fix. The vulnerability has a CVSS score of 8.8 (High), indicating a network-exploitable issue with low privileges but high impact on confidentiality, integrity, and availability. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been observed, and community discussion is minimal, users are strongly advised to upgrade to Grav version 1.7.42.2 or later as there are no known workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.42CPE matchmatch criteria | cpe:2.3:a:getgrav:grav:1.7.42:*:*:*:*:*:*:* | ||
1.7.42.1CPE matchmatch criteria | cpe:2.3:a:getgrav:grav:1.7.42.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.