← Back

CVE-2025-66295

nvd nist
Published: Dec 1, 2025Modified: Dec 4, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..\Nijat or ../Nijat), Grav writes the account YAML file to an unintended path outside user/accounts/. The written YAML can contain account fields such as email, fullname, twofa_secret, and hashed_password. This vulnerability is fixed in 1.8.0-beta.27.

Affected (27)

Products: Getgrav: Grav
1 product
Grav
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Getgrav
From 1.7.49.5 to 1.8.0
Version 1.8.0 beta10
Version 1.8.0 beta11
Version 1.8.0 beta12
Version 1.8.0 beta13
Version 1.8.0 beta14
Version 1.8.0 beta15
Version 1.8.0 beta16
Version 1.8.0 beta17
Version 1.8.0 beta18
Version 1.8.0 beta19
Version 1.8.0 beta1
Version 1.8.0 beta20
Version 1.8.0 beta21
Version 1.8.0 beta22
Version 1.8.0 beta23
Version 1.8.0 beta24
Version 1.8.0 beta25
Version 1.8.0 beta26
Version 1.8.0 beta2
Version 1.8.0 beta3
Version 1.8.0 beta4
Version 1.8.0 beta5
Version 1.8.0 beta6
Version 1.8.0 beta7
Version 1.8.0 beta8
Version 1.8.0 beta9

References (2)

Timeline

No history available yet.