PT-2026-51515 · Grav · Grav
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.0-beta.2
Description
An XML external entity (XXE) injection exists in the processing of SVG file uploads. Authenticated attackers can read arbitrary files by injecting XXE payloads via malicious SVG files. This occurs because the application utilizes the
simplexml load string() function without disabling the loading of external entities, which allows for the exfiltration of sensitive data.Recommendations
Update to version 2.0.0-beta.2 or later.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav