Grav CMS Path Traversal Vulnerability in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
A path traversal vulnerability in Grav CMS's MediaUploadTrait::deleteFile() allows authenticated users with media management permissions to delete arbitrary files on the server. This vulnerability has a CVSS score of 7.1 and is classified as CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').