Количество 2
Количество 2
CVE-2026-55885
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site configuration, through the backup download endpoint protected only by the session-static admin-nonce URL parameter. This issue is reported as fixed in version 1.7.53.
GHSA-2f86-9cp8-6hcf
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55885 Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site configuration, through the backup download endpoint protected only by the session-static admin-nonce URL parameter. This issue is reported as fixed in version 1.7.53. | CVSS3: 6.8 | 0% Низкий | 2 месяца назад | |
GHSA-2f86-9cp8-6hcf Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets | CVSS3: 6.8 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу