Grav Grav是Grav组织开源的一个基于文件系统的无数据库内容管理系统。 Grav 1.0.10之前版本存在输入验证错误漏洞,该漏洞源于POST /pages/{route}/move端点中的slug字段验证不当,PagesController::move()仅使用ltrim($body['slug'], '.')清理slug,未能中和'/'或'..'段,可能导致具有api.pages.write权限的已认证API调用者通过路径遍历攻击将整个页面目录移动到任意可写位置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: PROOF_c11b4b67159befac exfiltrated via path traversal - page directory moved to /tmp/pwned_proof/ (outside user/pages/)
| CVE-2026-65608 | 8.8 HIGH | Grav before 2.0.9 Remote Code Execution via FlexDirectory |
| CVE-2026-65897 | 8.8 HIGH | Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups |
| CVE-2026-65895 | 8.5 HIGH | Grav API Plugin before 1.0.10 Broken Access Control |
No comments yet