CVE-2024-27921

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 21, 2024
Updated: Jan 2, 2025
CWE ID 22

Summary

CVE-2024-27921 is a critical file upload path traversal vulnerability affecting Grav, an open-source content management system. This issue, present in versions prior to 1.7.45, enables attackers to manipulate file paths during uploads, potentially leading to arbitrary code injection on the server. Moreover, the vulnerability can be exploited to undermine the integrity of backup files by overwriting existing ones or creating new ones with malicious content. Attackers may also use CSS exfiltration techniques to steal sensitive data. To mitigate the risk, it is recommended that users upgrade to the patched version 1.7.45.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share