PT-2026-99340 · Grav+2 · Grav+2
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.25
Description
Web server configuration samples contain access-control deny rules that are matched case-sensitively. In the
web.config file for IIS, several deny rules (including user sensitive folders, user accounts, user data, user error redirect, user pages, system, vendor, and ignore folders) set ignoreCase="false" on the URL Rewrite <match> element. This overrides the IIS default and prevents case-insensitive fallback. On IIS running over case-insensitive NTFS, an unauthenticated remote attacker can bypass these rules by varying the case of a folder name or file extension, potentially disclosing sensitive data such as configuration secrets or account password hashes. The ability to retrieve files depends on MIME registration; for example, .json files are served by default, while .yaml or .yml files may return an HTTP 404.3 error unless a YAML MIME mapping is configured. A similar issue exists in lighttpd.conf where rules for user/(config|env), directory, script-extension, root-file, and dotfile lack the (?i) modifier, which enables case-insensitive matching.Recommendations
Update to version 2.0.25 and manually re-copy the corrected sample files for
web.config and lighttpd.conf after upgrading.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav
Iis
Lighttpd