CVE-2020-29556
15.03.2021, 18:15
The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
Vendor | Product | Version |
---|---|---|
getgrav | grav_cms | 𝑥 < 1.7.0 |
getgrav | grav_cms | 1.7.0:beta1 |
getgrav | grav_cms | 1.7.0:beta10 |
getgrav | grav_cms | 1.7.0:beta2 |
getgrav | grav_cms | 1.7.0:beta3 |
getgrav | grav_cms | 1.7.0:beta4 |
getgrav | grav_cms | 1.7.0:beta5 |
getgrav | grav_cms | 1.7.0:beta6 |
getgrav | grav_cms | 1.7.0:beta7 |
getgrav | grav_cms | 1.7.0:beta8 |
getgrav | grav_cms | 1.7.0:beta9 |
getgrav | grav_cms | 1.7.0:rc1 |
getgrav | grav_cms | 1.7.0:rc10 |
getgrav | grav_cms | 1.7.0:rc11 |
getgrav | grav_cms | 1.7.0:rc12 |
getgrav | grav_cms | 1.7.0:rc13 |
getgrav | grav_cms | 1.7.0:rc14 |
getgrav | grav_cms | 1.7.0:rc15 |
getgrav | grav_cms | 1.7.0:rc16 |
getgrav | grav_cms | 1.7.0:rc17 |
getgrav | grav_cms | 1.7.0:rc2 |
getgrav | grav_cms | 1.7.0:rc20 |
getgrav | grav_cms | 1.7.0:rc3 |
getgrav | grav_cms | 1.7.0:rc4 |
getgrav | grav_cms | 1.7.0:rc5 |
getgrav | grav_cms | 1.7.0:rc6 |
getgrav | grav_cms | 1.7.0:rc7 |
getgrav | grav_cms | 1.7.0:rc8 |
getgrav | grav_cms | 1.7.0:rc9 |
𝑥
= Vulnerable software versions