PT-2026-99344 · Unknown · Grav Data Manager
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav Data Manager versions 1.0.1 through 1.4.4
Description
Stored data entries in the item-detail view
admin/templates/partials/item.html.twig are rendered without proper escaping due to the use of Twig's raw filter. In certain instances, a striptags('<br>') call is used, which can be bypassed by PHP's strip tags() function by preserving allowed tags and their attributes. This allows an unauthenticated visitor to submit a front-end form and store an HTML payload. When an administrator views the entry in the classic admin panel, the payload executes as JavaScript within the administrator's session and origin, utilizing their privileges and CSRF token. Execution happens automatically for list values, such as checkbox or multi-select fields, and upon hovering for ordinary text fields.Recommendations
Update Grav Data Manager to version 1.4.5.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav Data Manager