← Back

CVE-2025-66302

nvd nist
Published: Dec 1, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Exploitability: 2.3 / Impact: 4.0
Source: NVD

Description

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative privileges to read arbitrary files on the underlying server filesystem. This vulnerability arises due to insufficient input sanitization in the backup tool, where user-supplied paths are not properly restricted, enabling access to files outside the intended webroot directory. The impact of this vulnerability depends on the privileges of the user account running the application. This vulnerability is fixed in 1.8.0-beta.27.

Affected (27)

Products: Getgrav: Grav
1 product
Grav
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Getgrav
Before 1.8.0
Version 1.8.0 beta10
Version 1.8.0 beta11
Version 1.8.0 beta12
Version 1.8.0 beta13
Version 1.8.0 beta14
Version 1.8.0 beta15
Version 1.8.0 beta16
Version 1.8.0 beta17
Version 1.8.0 beta18
Version 1.8.0 beta19
Version 1.8.0 beta1
Version 1.8.0 beta20
Version 1.8.0 beta21
Version 1.8.0 beta22
Version 1.8.0 beta23
Version 1.8.0 beta24
Version 1.8.0 beta25
Version 1.8.0 beta26
Version 1.8.0 beta2
Version 1.8.0 beta3
Version 1.8.0 beta4
Version 1.8.0 beta5
Version 1.8.0 beta6
Version 1.8.0 beta7
Version 1.8.0 beta8
Version 1.8.0 beta9

References (3)

Source: security-advisories@github.com
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.