CVE-2021-21425:
GravCMS RCE
CVE-2021-21425 is a critical improper access control issue in the Grav CMS Admin Plugin (versions 1.10.7 and earlier) where an unauthenticated attacker can invoke certain administrator controller methods and create or modify YAML files on the server. It was publicly disclosed in March 2021 and published as a CVE in early April 2021. In practice, this can lead to serious compromise—including configuration tampering and, in common attack chains, remote code execution—potentially letting an attacker take over the affected site.
Below are general examples of techniques, methods, and proof-of-concept approaches used to demonstrate this vulnerability in a controlled environment.
Waiting 1 seconds for http://$TARGET_IP/grav-admin/tmp/60fbe3228b8d5a7b.php creation! Initiating hacking session $ whoami www-data
9.3
Critical risk
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
Compexity
low
Privileges
none
Authentication
none
Affected
<=1.10.7
Patched
>1.10.7