Impact
Grav CMS before version 2.0.13 contains a server‑side template injection flaw in email‑action parameters. The unsandboxed "find" filter can be abused in the email subject, body, to, or from fields, allowing an attacker to inject arbitrary Twig payloads and trigger OS command execution.
Affected Systems
The affected product is Grav CMS, specifically versions prior to 2.0.13. Users who are low‑privileged page editors may submit forms that include email‑action parameters, creating the condition for exploitation.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. The attack requires an attacker to have editor access on the site and to submit a form containing crafted email‑action fields, after which arbitrary operating‑system commands are executed on the server.
OpenCVE Enrichment