Grav CMS
Discovery
nmap -sC -sV TARGET
# 22/tcp open ssh OpenSSH 8.2p1 Ubuntu
# 80/tcp open http Apache httpd 2.4.41
# http-title: Index of /
# http-ls: grav-admin/curl http://TARGET/grav-admin/
nuclei -u http://TARGET/grav-admin -as -rl 8 -c 6
# [metatag-cms] http://TARGET/grav-admin/ ["GravCMS"]
# [tech-detect:grav-cms] http://TARGET/grav-admin//grav-admin/admin
/grav-admin/login
/grav-admin/home
/grav-admin/forgot_password
/grav-admin/user_profile
/grav-admin/typography
/grav-admin/admin/login
/grav-admin/admin/forgotUsername Enumeration
CVE-2021-21425 Unauthenticated RCE
Post-Exploitation Enumeration
References
Last updated