GHSA-q6cm-x4f7-73r6CriticalCVSS 9.8
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController...
🔗 CVE IDs covered (1)
📋 Description
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.