Impact
Grav CMS versions prior to 2.0.13 do not validate the root path specified in backup profiles, allowing a configured traversal such as "../" to archive directories outside the intended GRAV_ROOT. This flaw is a classic path traversal vulnerability (CWE‑22) that permits an attacker who can edit backup profiles to read arbitrary files from critical locations like /opt, /mnt, or /srv, directly compromising confidentiality.
Affected Systems
The flaw affects all installations of Grav version 2.0 and later that are running before the 2.0.13 release. Users of the getgrav:grav product who have applied no patches past this version are at risk. No affected vendor version range is listed beyond the pre‑2.0.13 cutoff.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, but the vulnerability is only exploitable by users who already possess permission to edit backup profiles. No EPSS data is available, and the flaw is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet. Nonetheless, once a privileged user configures a malicious profile, sensitive files can be accessed without further action.
OpenCVE Enrichment