CVE-2024-27921
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-27921 is a critical file upload path traversal vulnerability affecting Grav, an open-source content management system. This issue, present in versions prior to 1.7.45, enables attackers to manipulate file paths during uploads, potentially leading to arbitrary code injection on the server. Moreover, the vulnerability can be exploited to undermine the integrity of backup files by overwriting existing ones or creating new ones with malicious content. Attackers may also use CSS exfiltration techniques to steal sensitive data. To mitigate the risk, it is recommended that users upgrade to the patched version 1.7.45.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Getgrav Grav