8.1

CVE-2020-29555

Exploit
The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GetgravGrav Cms Version < 1.7.0
GetgravGrav Cms Version1.7.0 Updatebeta1
GetgravGrav Cms Version1.7.0 Updatebeta10
GetgravGrav Cms Version1.7.0 Updatebeta2
GetgravGrav Cms Version1.7.0 Updatebeta3
GetgravGrav Cms Version1.7.0 Updatebeta4
GetgravGrav Cms Version1.7.0 Updatebeta5
GetgravGrav Cms Version1.7.0 Updatebeta6
GetgravGrav Cms Version1.7.0 Updatebeta7
GetgravGrav Cms Version1.7.0 Updatebeta8
GetgravGrav Cms Version1.7.0 Updatebeta9
GetgravGrav Cms Version1.7.0 Updaterc1
GetgravGrav Cms Version1.7.0 Updaterc10
GetgravGrav Cms Version1.7.0 Updaterc11
GetgravGrav Cms Version1.7.0 Updaterc12
GetgravGrav Cms Version1.7.0 Updaterc13
GetgravGrav Cms Version1.7.0 Updaterc14
GetgravGrav Cms Version1.7.0 Updaterc15
GetgravGrav Cms Version1.7.0 Updaterc16
GetgravGrav Cms Version1.7.0 Updaterc17
GetgravGrav Cms Version1.7.0 Updaterc2
GetgravGrav Cms Version1.7.0 Updaterc20
GetgravGrav Cms Version1.7.0 Updaterc3
GetgravGrav Cms Version1.7.0 Updaterc4
GetgravGrav Cms Version1.7.0 Updaterc5
GetgravGrav Cms Version1.7.0 Updaterc6
GetgravGrav Cms Version1.7.0 Updaterc7
GetgravGrav Cms Version1.7.0 Updaterc8
GetgravGrav Cms Version1.7.0 Updaterc9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.16% 0.882
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvd@nist.gov 5.5 8 4.9
AV:N/AC:L/Au:S/C:N/I:P/A:P
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.