# CVE-2021-21425 — getgrav grav-plugin-admin

> As of 2024-08-03, CVE-2021-21425 is a CRITICAL-severity vulnerability in getgrav grav-plugin-admin, CVSS v3.1 9.3, EPSS 80.6% (99.6th percentile). No Threadlinqs-tracked threat campaign has been attributed to CVE-2021-21425 as of 2024-08-03; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

**Last updated:** 2024-08-03

## What is CVE-2021-21425?

Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any credentials. Particular method execution will result in arbitrary YAML file creation or content change of existing YAML files on the system. Successfully exploitation of that vulnerability results in configuration changes, such as general site information change, custom scheduler job definition, etc. Due to the nature of the vulnerability, an adversary can change some part of the webpage, or hijack an administrator account, or execute operating system command under the context of the web-server user. This vulnerability is fixed in version 1.10.8. Blocking access to the `/admin` path from untrusted sources can be applied as a workaround.

The record classifies CVE-2021-21425 under weakness class [CWE-284](https://intel.threadlinqs.com/cwe/CWE-284). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction, and has high impact on integrity. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 2012 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 9.3 — CRITICAL (`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N`)
- **EPSS (FIRST):** 80.6% probability of exploitation in the next 30 days, higher than 99.6% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 10/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2021-04-07, last modified 2024-08-03

## Is CVE-2021-21425 being exploited?

Weaponised exploit code for CVE-2021-21425 is publicly available. 6 public proof-of-concept repositories are tracked for this identifier. It currently carries a trending score of 38 in the Threadlinqs vulnerability feed.

- [CsEnox/CVE-2021-21425](https://github.com/CsEnox/CVE-2021-21425) (github)
- [bluetoothStrawberry/cve-2021-21425](https://github.com/bluetoothStrawberry/cve-2021-21425) (github)
- [grey-master-a/GravCMS_Nmap_Script](https://github.com/grey-master-a/GravCMS_Nmap_Script) (github)
- [afifudinmtop/CVE-2021-21425](https://github.com/afifudinmtop/CVE-2021-21425) (github)
- [s1lentf00thold/CVE-2021-21425-RCE](https://github.com/s1lentf00thold/CVE-2021-21425-RCE) (github)
- [trickest/cve](https://github.com/trickest/cve/blob/main/2021/CVE-2021-21425.md) (trickest)

## Affected products and versions

- **getgrav**: grav-plugin-admin

## How to fix CVE-2021-21425

No vendor patch reference has been recorded for CVE-2021-21425 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

## Threat activity tracking CVE-2021-21425

No threat campaign in the Threadlinqs corpus currently references CVE-2021-21425, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

## Sources

Enriched from CVE.org, FIRST EPSS, public proof-of-concept repositories. Last verified by Threadlinqs on 2026-10-10.

**Vendor advisory and patch**

- [github.com](https://github.com/getgrav/grav-plugin-admin/security/advisories/GHSA-6f53-6qgv-39pj)

**Other references**

- [pentest.blog](https://pentest.blog/unexpected-journey-7-gravcms-unauthenticated-arbitrary-yaml-write-update-leads-to-code-execution/)
- [packetstormsecurity.com](http://packetstormsecurity.com/files/162283/GravCMS-1.10.7-Remote-Command-Execution.html)
- [packetstormsecurity.com (GravCMS 1.10.7 Remote Command Execution)](http://packetstormsecurity.com/files/162457/GravCMS-1.10.7-Remote-Command-Execution.html)

Canonical: https://intel.threadlinqs.com/cve/CVE-2021-21425
Full detection coverage and IOCs for threats exploiting CVE-2021-21425 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
