First published: Fri Nov 05 2021(Updated: )
grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Getgrav Grav | <=1.7.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3924 is a vulnerability in the Grav CMS that allows an attacker to perform a path traversal attack, potentially accessing restricted directories.
CVE-2021-3924 has a severity rating of 7.5 (High).
CVE-2021-3924 affects the Grav CMS version 1.7.24 and prior, allowing for path traversal attacks.
To fix the CVE-2021-3924 vulnerability, update your Grav CMS installation to version 1.7.25 or later.
You can find more information about CVE-2021-3924 in the references provided: [Github commit](https://github.com/getgrav/grav/commit/8f9c417c04b89dc8d2de60b95e7696821b2826ce) and [Huntr bounty](https://huntr.dev/bounties/7ca13522-d0c9-4eff-a7dd-6fd1a7f205a2).