PT-2025-48561 · Grav Cms · Grav Cms
Published
2025-12-01
·
Updated
2025-12-02
·
CVE-2025-66302
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 1.8.0-beta.27
Description
Grav CMS contains a path traversal flaw. Authenticated attackers with administrative privileges can read arbitrary files on the server filesystem. This is due to inadequate input sanitization within the backup tool, where user-provided paths are not sufficiently restricted, allowing access to files outside the webroot directory. The impact of this issue is dependent on the privileges of the user account running the application.
Recommendations
Update to version 1.8.0-beta.27 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav Cms