PT-2026-81139 · Grav Cms · Grav Cms
CVSS v4.0
8.6
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav CMS versions prior to 2.0.16
Description
A symlink following issue exists in the
createLockFile() function of the Scheduler Job. Local attackers can overwrite arbitrary files by pre-creating symbolic links (symlinks) at predictable lock file paths within the world-writable temporary directory. By pointing a symlink to a file that the web server process has permission to write to, the next scheduled job execution will follow the link and overwrite the target file's content with the job ID string.Recommendations
Update Grav CMS to version 2.0.16 or later.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav Cms