CVE-2020-11529
medium · 6.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
6.1
CVSS
10.9%
EPSS (exploit prob.)
96th
EPSS percentile
2020-04-04
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-601
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| getgrav | grav | <= 1.6.31 |
Check a specific version with /api/v1/cve/match.
References
- https://getgrav.org/#changelog
- https://github.com/getgrav/grav/commit/2eae104c7a4bf32bc26cb8073d5c40464bfda3f7
- https://github.com/getgrav/grav/issues/3134
- https://getgrav.org/#changelog
- https://github.com/getgrav/grav/commit/2eae104c7a4bf32bc26cb8073d5c40464bfda3f7
- https://github.com/getgrav/grav/issues/3134
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-11529