CVE-2025-50286 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install i…
High CVSS: 8.1

CVE-2025-50286

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and reverse shell access.
Vendor
Getgrav
Product
Grav
CWE
CWE-434
Yayın Tarihi
2025-08-06 15:15:32
Güncelleme
2025-11-07 19:18:37
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar