Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Grav: Anonymous Page Content Overwrite via Form File Upload filename Override
Vulnerability Description
The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-supplied filename and hard-block page-content extensions (`md`, `yaml`, `yml`, `json`, `twig`, `ini`) regardless of the configurable dangerous-extensions list. A permissive `accept` policy combined with the default `destination: self@` could otherwise let an attacker overwrite the page's own `.md` and pivot to super-admin via a `process: save` action. This vulnerability is fixed in 9.1.0.
CVSS Information
N/A
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
Grav CMS 安全漏洞
Vulnerability Description
Grav CMS是Grav开源的一个基于文件的扁平化内容管理系统。 Grav CMS 9.1.0之前版本存在安全漏洞,该漏洞源于文件上传时未剥离路径组件且未硬性阻止页面内容扩展名,可能导致未认证用户覆盖页面内容。
CVSS Information
N/A
Vulnerability Type
N/A