Lucene search

K
osvGoogleOSV:CVE-2020-29556
HistoryMar 15, 2021 - 6:15 p.m.

CVE-2020-29556

2021-03-1518:15:17
Google
osv.dev
5
grav cms
backup functionality
vulnerability
unauthorized file access
path traversal
csrf protection

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

45.2%

The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

45.2%

Related for OSV:CVE-2020-29556