Headline
GHSA-cxgw-r5jg-7xwq: Code injection in grav
Grav is vulnerable to Server Side Template Injection via Twig. According to a previous vulnerability report, Twig should not render dangerous functions by default, such as system.
Code injection in grav
Critical severity GitHub Reviewed Published Jun 30, 2022 • Updated Jul 5, 2022
Related news
CVE-2022-2073: Fixed Twig `|filter()` allowing code execution · getgrav/grav@9d6a2db
Code Injection in GitHub repository getgrav/grav prior to 1.7.34.