← Back

CVE-2020-29555

nvd nist
Published: Mar 15, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)

Affected (29)

Products: Getgrav: Grav Cms
1 product
Grav Cms
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Getgrav
Before 1.7.0
Version 1.7.0 beta10
Version 1.7.0 beta1
Version 1.7.0 beta2
Version 1.7.0 beta3
Version 1.7.0 beta4
Version 1.7.0 beta5
Version 1.7.0 beta6
Version 1.7.0 beta7
Version 1.7.0 beta8
Version 1.7.0 beta9
Version 1.7.0 rc10
Version 1.7.0 rc11
Version 1.7.0 rc12
Version 1.7.0 rc13
Version 1.7.0 rc14
Version 1.7.0 rc15
Version 1.7.0 rc16
Version 1.7.0 rc17
Version 1.7.0 rc1
Version 1.7.0 rc20
Version 1.7.0 rc2
Version 1.7.0 rc3
Version 1.7.0 rc4
Version 1.7.0 rc5
Version 1.7.0 rc6
Version 1.7.0 rc7
Version 1.7.0 rc8
Version 1.7.0 rc9

References (2)

Timeline

No history available yet.