CVE-2025-50286 | Grav CMS 1.7.48 direct-install unrestricted upload
A vulnerability classified as critical has been found in Grav CMS 1.7.48. This affects an unknown part of the file /admin/tools/direct-install. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-50286. It is possible to initiate the attack remotely. There is no exploit available.