PT-2026-85501 · Unknown · Grav Admin
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Grav Admin versions prior to 2.0.20
Description
Insufficient sanitization of output from the
marked.parse() function before it is injected into the Document Object Model (DOM) via Svelte's {@html} directive within the MarkdownEditor and MarkdownModal components. This allows attackers to inject javascript: URI schemes into plugin or theme changelogs, leading to arbitrary code execution in authenticated administrator sessions.Recommendations
Update Grav Admin to version 2.0.20 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav Admin