CVE-2025-50286: Malicious File Upload
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and reverse shell access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50286?
CVE-2025-50286 has been classified as a critical Remote Code Execution vulnerability.
How do I fix CVE-2025-50286?
To fix CVE-2025-50286, upgrade Grav CMS to the latest version where the vulnerability is addressed.
Who is affected by CVE-2025-50286?
CVE-2025-50286 affects users of Grav CMS v1.7.48 who have admin access.
What is the attack vector for CVE-2025-50286?
The attack vector for CVE-2025-50286 is through the /admin/tools/direct-install interface allowing malicious plugin uploads.
What are the consequences of CVE-2025-50286?
Exploitation of CVE-2025-50286 can lead to arbitrary PHP code execution and reverse shell access on the server.