PT-2025-48561 · Grav Cms · Grav Cms

Published

2025-12-01

·

Updated

2025-12-02

·

CVE-2025-66302

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.8.0-beta.27
Description Grav CMS contains a path traversal flaw. Authenticated attackers with administrative privileges can read arbitrary files on the server filesystem. This is due to inadequate input sanitization within the backup tool, where user-provided paths are not sufficiently restricted, allowing access to files outside the webroot directory. The impact of this issue is dependent on the privileges of the user account running the application.
Recommendations Update to version 1.8.0-beta.27 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-66302
GHSA-J422-QMXP-HV94

Affected Products

Grav Cms