CVE-2020-29555: Path Traversal
The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-29555?
CVE-2020-29555 is a vulnerability in Grav CMS that allows an authenticated attacker to delete arbitrary files on the server.
How severe is CVE-2020-29555?
CVE-2020-29555 has a severity score of 8.1 (high).
Is an unauthenticated attacker able to exploit CVE-2020-29555?
Yes, an unauthenticated attacker can also exploit CVE-2020-29555.
How can I fix CVE-2020-29555?
To fix CVE-2020-29555, update Grav CMS to version 1.7.0-rc.18 or later.
Where can I find more information about CVE-2020-29555?
You can find more information about CVE-2020-29555 at this link: https://blog.bssi.fr/cve-2020-29553-cve-2020-29555-cve-2020-29556-multiple-vulnerabilities-within-cms-grav/