← volver
CVE-2025-66301highCWE-285

Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions

36Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 8.6epss 1.4%
de la publicación al arma0 días
Publicada en NVD1 dic
metasploit1 dic
probabilidad de explotación
1.4%top 31% de las CVE
explotación observada
noninguna fuente lo reporta
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the form is now able to change the functioning of the form through modifying the content of the data[_json][header][form] which is the YAML frontmatter which includes the process section which dictates what happens after a user submits the form which include some important actions that could lead to further vulnerabilities. This vulnerability is fixed in 1.8.0-beta.27.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
getgrav · grav