CVE-2024-27921 is a critical file upload path traversal vulnerability affecting Grav, an open-source flat-file content management system, in versions prior to 1.7.45. This flaw allows authenticated attackers to replace or create arbitrary files, including those with sensitive extensions like .json or .zip, leading to potential arbitrary code injection, data exfiltration via CSS, and integrity compromise of backup files. With a CVSS score of 8.8 (HIGH), it has a low attack complexity and no user interaction required, posing a significant risk of complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in the KEV catalog, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.45CPE matchmatch criteria | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.