PT-2025-48563 · Grav · Grav

CVE-2025-66304

·

Publicado

2025-12-01

·

Atualizado

2025-12-02

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.8.0-beta.27
Description Grav is a file-based Web platform. Users with read access to the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure could allow an attacker to gain elevated privileges if they are able to crack the password hashes.
Recommendations Update to version 1.8.0-beta.27 or later.

Exploit

Correção

LPE

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66304
GHSA-GQ3G-666W-7H85

Produtos afetados

Grav