Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
Updated vendor to Grav, product to Grav CMS, set affected versions to 1.7.x, changed severity to HIGH, and marked as actively exploited.
Initial creation