PT-2025-48555 · Unknown+1 · Grav Admin Plugin+1
Published
2025-12-01
·
Updated
2025-12-01
·
CVE-2025-66296
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 1.8.0-beta.27
Description
Grav’s Admin plugin contains a flaw where the creation of new user accounts does not validate username uniqueness. This allows a user with create user permission to create an account with the same username as an existing administrator account, effectively gaining administrator access through privilege escalation. The
username is not properly validated during account creation, allowing an attacker to overwrite administrator credentials with a new password and email.Recommendations
Update to Grav version 1.8.0-beta.27 or later.
Exploit
Fix
LPE
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav
Grav Admin Plugin