CVE-2021-3924: Path Traversal in getgrav/grav
grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-3924?
CVE-2021-3924 is a vulnerability in the Grav CMS that allows an attacker to perform a path traversal attack, potentially accessing restricted directories.
What is the severity of CVE-2021-3924?
CVE-2021-3924 has a severity rating of 7.5 (High).
How does CVE-2021-3924 affect the Grav CMS?
CVE-2021-3924 affects the Grav CMS version 1.7.24 and prior, allowing for path traversal attacks.
How can I fix the CVE-2021-3924 vulnerability?
To fix the CVE-2021-3924 vulnerability, update your Grav CMS installation to version 1.7.25 or later.
Where can I find more information about CVE-2021-3924?
You can find more information about CVE-2021-3924 in the references provided: [Github commit](https://github.com/getgrav/grav/commit/8f9c417c04b89dc8d2de60b95e7696821b2826ce) and [Huntr bounty](https://huntr.dev/bounties/7ca13522-d0c9-4eff-a7dd-6fd1a7f205a2).