grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
Link | Tags |
---|---|
https://huntr.dev/bounties/c2bc65af-7b93-4020-886e-8cdaeb0a58ea | patch third party advisory exploit |
https://github.com/getgrav/grav/commit/c51fb1779b83f620c0b6f3548d4a96322b55df07 | third party advisory |