CVE-2020-29556: Path Traversal
The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-29556?
CVE-2020-29556 is a vulnerability in Grav CMS that allows an authenticated attacker to read arbitrary local files on the underlying server.
How severe is CVE-2020-29556?
CVE-2020-29556 has a severity rating of 5.5 (medium).
Who is affected by CVE-2020-29556?
Users of Grav CMS versions up to 1.7.0-rc.17 are affected by CVE-2020-29556.
Is authentication required to exploit CVE-2020-29556?
Yes, authentication is required to exploit CVE-2020-29556.
Is there a fix available for CVE-2020-29556?
A fix for CVE-2020-29556 may be available in the latest version of Grav CMS. It is recommended to update to the latest version to mitigate this vulnerability.