CVE-2020-29553
PHP vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2020-29553) affects the Scheduler component in Grav CMS through version 1.7.0-rc.17. This security flaw was discovered and recorded on December 4, 2020, and allows an attacker to execute system commands by tricking an administrator into visiting a malicious website through a Cross-Site Request Forgery (CSRF) attack (MITRE CVE).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. It is classified as CWE-352 (Cross-Site Request Forgery) and requires user interaction for successful exploitation. The CVSS v2.0 score is 5.1 (MEDIUM) with the vector (AV:N/AC:H/Au:N/C:P/I:P/A:P) (NVD).

Impact

If successfully exploited, this vulnerability allows attackers to execute system commands with the privileges of the admin user who visits the malicious website. This could lead to complete system compromise, including potential data theft, system manipulation, and service disruption (NVD).

Exploitability

The vulnerability requires user interaction, specifically requiring an administrator to visit a malicious website. The attack can be executed remotely, and no authentication is required to launch the attack, though it does require the target to be an authenticated administrator (NVD).

Mitigation and workarounds

Affected users should upgrade their Grav CMS installations to a version newer than 1.7.0-rc.17. The vulnerability affects all versions up to and including 1.6.31 and all 1.7.0 beta and release candidate versions through rc.17 (NVD).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-wg23-69c2-gjc8CRITICAL9.1
  • PHP logoPHP
  • craftcms/cms
NoYesAug 07, 2026
CVE-2026-71488HIGH7.5
  • PHP logoPHP
  • commonmark
NoYesAug 06, 2026
CVE-2026-62996MEDIUM6.9
  • PHP logoPHP
  • smarty/smarty
NoYesAug 07, 2026
CVE-2026-62992MEDIUM6.9
  • PHP logoPHP
  • smarty/smarty
NoYesAug 07, 2026
CVE-2026-71478MEDIUM6.1
  • PHP logoPHP
  • commonmark
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management