In Grav Admin Plugin versions 1.10.7 and earlier, an unauthenticated attacker can execute certain administrator controller methods without credentials. This allows arbitrary creation or modification of YAML files, leading to configuration changes, custom scheduler job definitions, and potentially arbitrary code execution under the web server user context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Small standalone Python exploit repository with three files: LICENSE, a brief README, and a single executable script exploit.py. The script targets Grav CMS 1.10.7 and explicitly references CVE-2021-21425. Its workflow is straightforward: it sends a GET request to the target's /admin page to scrape an admin nonce and capture a Set-Cookie value, then submits a crafted POST request to /admin/config/scheduler to create an enabled custom scheduler job. That job runs /usr/bin/php with inline PHP code that decodes a base64 payload and executes system() on a reverse shell command. The default payload is a bash reverse shell using /dev/tcp to connect back to the supplied LHOST and LPORT; a Python reverse shell alternative is present but commented out. The exploit does not deploy a persistent webshell and instead relies on Grav's scheduler to trigger execution within about a minute. There is no framework usage, no obfuscation beyond base64 wrapping of the PHP command, and no detection-only logic; this is a direct operational RCE exploit intended to obtain interactive shell access on a vulnerable Grav CMS host.
This repository is a small standalone Python proof-of-concept exploit for CVE-2021-21425, targeting GravCMS/Grav Admin plugin unauthenticated remote code execution through arbitrary YAML scheduler configuration writes. The repository contains only three files: a LICENSE, a README with usage and vulnerability background, and a single executable script, exploit.py, which is the main entry point. The exploit workflow is straightforward and operational: it creates a requests session, performs an unauthenticated GET to the target's /admin page, extracts the admin-nonce value from the HTML using a regex, then submits a crafted application/x-www-form-urlencoded POST to /admin/config/scheduler. The POST body defines a malicious custom scheduler job named ncefs that runs /usr/bin/php with a -r eval(base64_decode(...)) argument. The embedded PHP writes a decoded shell command into /tmp/rev.sh, marks it executable, and runs it with bash. The script supports two modes via CLI arguments: reverse shell mode (-s LHOST LPORT), which generates a bash reverse shell using /dev/tcp/LHOST/LPORT, and custom command mode (-c), which executes an arbitrary attacker-supplied command. Payload content is automatically base64-encoded before insertion into the PHP wrapper, improving usability over the original referenced Exploit-DB version. This is a real exploit rather than a detector. It does not merely verify exposure; it actively modifies scheduler configuration to obtain code execution. It is best classified as OPERATIONAL because it includes a working payload path and attacker-controlled command execution, but it is not part of a larger exploitation framework and does not provide extensive payload modularity beyond basic CLI parameters.
Small standalone Python exploit repository for CVE-2021-21425 targeting GravCMS/Grav Admin. Repository contains only three files: MIT LICENSE, a README describing the vulnerability and usage, and a single executable script (exploit.py). The Python script is the sole entry point and uses argparse plus requests to automate exploitation. Exploit flow: it sends a GET request to the target's /admin page, extracts the admin-nonce value from HTML using regex, then submits a crafted application/x-www-form-urlencoded POST to /admin/config/scheduler. The POST creates a malicious custom scheduler job named ncefs that runs /usr/bin/php with a base64-decoded PHP one-liner. That PHP writes a shell script to /tmp/rev.sh and executes it. In default mode the shell script contains a bash reverse shell to attacker-supplied LHOST:LPORT using /dev/tcp; in alternate mode the operator can supply any arbitrary command with -c. Capabilities: unauthenticated web-based RCE, arbitrary command execution, reverse shell staging, and persistence until the scheduled task is removed. The cron expression is hardcoded to run every minute, so exploitation is not instant but operationally usable. The script includes basic error handling, CLI parameterization, and automatic base64 encoding of payloads, making it more usable than a bare PoC. No framework affiliation is evident.
Repository contains a single Python exploit (exploit.py) and a short README. The exploit targets GravCMS (noted as 1.10.7) CVE-2021-21425, leveraging an unauthenticated arbitrary YAML write/update via the Grav admin scheduler configuration. Core flow in exploit.py: - Uses requests.Session() to GET {target}/admin and regex-extracts the hidden form value admin-nonce. - Crafts an application/x-www-form-urlencoded POST to {target}/admin/config/scheduler with parameters that define/enable a custom scheduler job. - The job runs /usr/bin/php with arguments that execute: php -r eval(base64_decode("<payload>")); - The payload is PHP that writes /tmp/rev.sh (containing a base64-decoded bash reverse shell), chmods it, and executes it. The README instructs the operator to change the target IP and replace the base64-encoded reverse shell, then listen with netcat. Overall purpose: obtain remote code execution and a reverse shell on a vulnerable GravCMS instance via network-accessible admin scheduler endpoints.
This repository contains a single Metasploit module (modules/exploits/linux/http/gravcms_exec.rb) that exploits CVE-2021-21425, a remote code execution vulnerability in GravCMS (versions 1.10.7 and earlier) with the Admin plugin enabled. The exploit leverages an unauthenticated arbitrary YAML write/update flaw, allowing an attacker to create or modify configuration files, specifically the scheduler configuration, to execute arbitrary PHP code as the web server user. The module is weaponized, supporting customizable PHP payloads (defaulting to a Meterpreter reverse shell) and includes logic for both exploitation and cleanup. The main attack vector is network-based, targeting the /admin and /admin/config/scheduler HTTP endpoints. The repository is structured as a typical Metasploit exploit module, written in Ruby, and is ready for operational use within the Metasploit framework.
This repository contains a Python exploit targeting GravCMS version 1.10.7 (CVE-2021-21425), which allows unauthenticated arbitrary file write via the scheduler configuration. The exploit works by first retrieving an 'admin-nonce' and session cookie from the /admin endpoint, then submitting a malicious scheduled task to /admin/config/scheduler that writes a base64-encoded PHP web shell to the /tmp directory. After a short wait for the shell to be created, the script provides an interactive shell interface, allowing the attacker to execute arbitrary commands on the target server via HTTP POST requests to the web shell. The repository consists of a single exploit script (exploit.py) and a README.md with usage instructions. The exploit is operational and provides a working payload (PHP web shell), making it a practical tool for post-exploitation activities on vulnerable GravCMS installations.
This repository contains a Python exploit (exploit.py) targeting GravCMS (Grav Admin 1.7.10) for CVE-2021-21425, an unauthenticated arbitrary YAML write/update vulnerability that leads to remote code execution. The exploit works by first accessing the /admin endpoint to retrieve a security nonce, then using the /admin/config/scheduler endpoint to create a scheduled task that writes an attacker-supplied shell command to /tmp/shell.sh. It then schedules another task to execute this shell script, effectively running arbitrary commands on the target server. The exploit is unauthenticated and requires only network access to the GravCMS admin interface. The repository also includes a brief README describing the vulnerability and referencing an external blog post for further details.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.