Lucene search

K
osvGoogleOSV:GHSA-GPMF-Q5JH-HJX4
HistoryMay 24, 2022 - 5:44 p.m.

Grav CMS Arbitrary File Deletion

2022-05-2417:44:32
Google
osv.dev
7

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.2%

The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.2%

Related for OSV:GHSA-GPMF-Q5JH-HJX4