CVE-2020-29555 affects Grav CMS through version 1.7.0-rc.17, allowing authenticated attackers to delete arbitrary files via a path traversal vulnerability in the BackupDelete function. This high-severity vulnerability (CVSS 8.1) is easily exploitable over the network with low complexity and no user interaction, potentially leading to significant data integrity and availability impacts. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for unauthenticated exploitation due to a lack of CSRF protection makes it a notable risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:getgrav:grav_cms:*:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:getgrav:grav_cms:1.7.0:beta1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:getgrav:grav_cms:1.7.0:beta10:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:getgrav:grav_cms:1.7.0:beta2:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:getgrav:grav_cms:1.7.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.