A Server-Side Template Injection (SSTI) vulnerability exists in Grav CMS prior to version 1.7.45. The flaw allows any authenticated user with editor permissions to inject and execute arbitrary code on the server, bypassing the intended security sandbox. This is due to insufficient input sanitization in the template rendering functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small reproduction and analysis package for CVE-2024-28116 affecting Grav CMS. It is not a standalone automated exploit tool; instead, it provides two Dockerized environments—`vulnerable/` for Grav 1.7.44 and `patched/` for Grav 1.7.45—plus a README that documents manual exploitation steps and explains the root cause. Repository structure is minimal: two Dockerfiles build Apache/PHP containers that download specific Grav Admin release ZIPs from GitHub, and matching Apache virtual host configs expose the application from `/var/www/html`. The vulnerable image installs Grav 1.7.44, while the patched image installs 1.7.45 for comparison. The exploit capability described in the README is authenticated web-based RCE via SSTI and Twig sandbox bypass. A low-privileged editor user creates a page, enables Twig processing, and inserts a Twig payload that accesses `grav.twig.twig_vars['config']` to modify the `system.twig.safe_functions` whitelist at runtime. After adding `system` to the whitelist, the payload calls `system('id')`, demonstrating command execution as `www-data`. This makes the exploit a proof-of-concept for privilege abuse within the Grav admin workflow rather than a remote unauthenticated exploit. No exploit automation code is present; the README contains the operative payload and step-by-step instructions. The patched environment demonstrates that version 1.7.45 blocks the dangerous directive through `cleanDangerousTwig()` in `Security.php`, preventing whitelist modification and command execution.
This repository contains a single Python exploit script (GenGravSSTIExploit.py) targeting an authenticated Server-Side Template Injection (SSTI) vulnerability in Grav CMS versions <= 1.7.44 (CVE-2024-28116). The exploit requires valid editor credentials for the Grav CMS admin panel. The script automates the process of logging in, creating a new page, and injecting a Twig template payload that enables arbitrary OS command execution via the 'do' query parameter. The README provides detailed usage instructions and example output. The exploit is a proof-of-concept (POC) and does not include advanced features such as credential brute-forcing or post-exploitation modules. The only code file is GenGravSSTIExploit.py, and the repository also includes a license, a requirements.txt for dependencies, and a comprehensive README.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-28116, an authenticated Server-Side Template Injection (SSTI) vulnerability in Grav CMS versions <=1.7.44. The main file, 'graver.py', is a Python script that automates the exploitation process. It requires valid editor credentials for the target Grav CMS instance, which must be hardcoded into the script. The script performs the following steps: (1) logs into the Grav CMS admin console, (2) creates a new page with a malicious SSTI payload, and (3) provides a URL to the attacker where remote OS commands can be executed via the web interface. The README.md provides usage instructions and an example, including a sample endpoint for the injected page. The repository is structured simply, with a license, a README, and the exploit script. The exploit is a functional PoC and does not include advanced payload customization or post-exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.