PT-2026-81146 · Grav · Email Plugin
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav Email plugin versions prior to 4.2.2
Description
An authenticated remote user with
api.access and api.pages.write permissions can execute arbitrary operating-system commands as the account running PHP. This occurs because the plugin renders Email action parameters controlled by the page editor as unsandboxed Twig templates. An attacker can achieve this by placing a Twig expression in the header.form.process.email.body parameter, publishing the page, and submitting the form. Twig is a template engine used to generate HTML or other text formats dynamically.Recommendations
Update Grav Email plugin to version 4.2.2 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Email Plugin