CVE-2025-66302

MEDIUM EPSS 33.0%
Published Dec 1, 20257mo ago · Modified Jun 17, 20261w ago
6.8 CVSS 3.1
Medium
Find Similar
Published Dec 1, 2025 7mo ago
Last Modified Jun 17, 2026 1w ago

Description

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative privileges to read arbitrary files on the underlying server filesystem. This vulnerability arises due to insufficient input sanitization in the backup tool, where user-supplied paths are not properly restricted, enabling access to files outside the intended webroot directory. The impact of this vulnerability depends on the privileges of the user account running the application. This vulnerability is fixed in 1.8.0-beta.27.

CVSS Details

Base Score
6.8
Exploitability
2.3
Impact
4.0
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Changed
Confidentiality High
Integrity None
Availability None

Threat Intelligence

EPSS Exploit Probability
33.0% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-22 Path Traversal Resource Mgmt

Affected Products 27

VendorProductVersionRange
getgravgrav* <1.8.0
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any
getgravgrav1.8.0any

References 2

  • github.com https://github.com/getgrav/grav/commit/ed640a13143c4177af013cf001969ed2c5e197ee
    Patch
  • github.com https://github.com/getgrav/grav/security/advisories/GHSA-j422-qmxp-hv94
    ExploitThird Party Advisory

Remediation

  • github.com https://github.com/getgrav/grav/commit/ed640a13143c4177af013cf001969ed2c5e197ee
    Patch