PT-2025-48551 · Grav · Grav
Published
2025-12-01
·
Updated
2025-12-04
·
CVE-2025-66295
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 1.8.0-beta.27
Description
Grav is a file-based Web platform. A user with user creation privileges can create a new user through the Admin UI and, by supplying a username containing path traversal sequences (for example
../Nijat or ..Nijat), cause Grav to write the account YAML file to an unintended path outside the user/accounts/ directory. The written YAML file can contain account fields such as email, fullname, twofa secret, and hashed password.Recommendations
Update to version 1.8.0-beta.27 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav