PT-2026-67411 · Grav Cms · Grav Cms
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav CMS version 2.0.10
Description
A path traversal issue exists in the
ImageMedium::watermark() function, which passes an unsanitized $image argument to RocketThemeToolboxResourceLocatorUniformResourceLocator::findResource(). The file:// scheme branch only performs lexical collapse of .. segments without verifying the real path or containment. This allows an editor using Markdown image syntax with traversal sequences to include arbitrary image files from outside the media sandbox into a carrier image. The resulting image is cached and served via a public, unauthenticated URL, leading to the disclosure of files to anonymous visitors.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav Cms