CVE-2025-66844

CRITICAL9.1EPSS 0.06%

Grav may be vulnerable to SSRF attack via Twig Templates

發布日:2025/12/15修改日:2025/12/17

描述

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

參考連結(3)