← Back to browse · API

CVE-2024-27921

Severity
HIGH
CVSS
8.8
EPSS
0.60585
Risk score
56.4
CISA KEV
No
PoC
No
Published
2024-03-21
Modified
2025-04-10
First seen
2026-08-07
Aliases
EUVD-2024-0961, GHSA-M7HX-HW6H-MQMC
Products
getgrav:grav, getgrav:grav < 1.7.45
Sources
euvd EUVD-2024-0961

Description

Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling attackers to replace or create files with extensions like .json, .zip, .css, .gif, etc. This critical security flaw poses severe risks, that can allow attackers to inject arbitrary code on the server, undermine integrity of backup files by overwriting existing files or creating new ones, and exfiltrate sensitive data using CSS exfiltration techniques. Upgrading to patched version 1.7.45 can mitigate the issue.

References