Impact
Grav CMS suffered an arbitrary file write flaw caused by an incomplete denylist in its Blueprint dynamic data validation. The bug permits attackers to invoke the PHP error_log function through a data directive, allowing malicious developers to append PHP payloads to web‑accessible files. The result is the possibility of full remote code execution on the affected system.
Affected Systems
The vulnerability is present in all Grav releases prior to 2.0.15. Attackers must have page‑edit or blueprint‑config permissions, and any entity with that level of access can trigger the exploit.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, and while the EPSS score is not available the risk appears high. Not listed in the CISA KEV catalog, the flaw remains a substantial threat when an attacker can leverage legitimate content editing privileges to inject executable code, giving them persistent remote control of the site.
OpenCVE Enrichment