216.73.217.22

CVE-2021-47812

· Published 16/01/2026 00:16 · Modified 16/01/2026 22:16

Labels: CVE-2021-47812 2026-01-16CVE-2021-47812CWE-862[email protected]

Essential information

Published
16/01/2026 00:16
Modified
16/01/2026 22:16
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded payloads and create malicious custom jobs with system command execution.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gravcms / gravcms cpe:2.3:a:gravcms:gravcms:1.10.7:*:*:*:*:*:*:*

References