Vulnerabilidad · Publicado 18/08/2026
grav-plugin-api versiones anteriores a 1.0.15 no validan correctamente contenido Twig en el endpoint translate(), permitiendo a atacantes con permisos api.pages.write ejecutar inyecciones de plantillas del lado del servidor. Los atacantes pueden manipular parámetros de encabezado y contenido para evaluar cargas útiles maliciosas durante la renderización de páginas, comprometiendo la integridad del servidor.
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are evaluated at render time.
Score: 8.1/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-1336
Publicado en NIST NVD.