CVE-2025-50286 | Grav CMS 1.7.48 direct-install unrestricted upload (EDB-52402)
A vulnerability described as critical has been identified in Grav CMS 1.7.48. This affects an unknown part of the file /admin/tools/direct-install. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-50286. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.