PT-2025-48565 · Grav Cms · Grav Cms

Published

2025-12-01

·

Updated

2025-12-02

·

CVE-2025-66306

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.8.0-beta.27
Description Grav CMS contains an Insecure Direct Object Reference (IDOR) issue within its Admin Panel. This allows users with limited privileges to access sensitive information belonging to other accounts. While full account takeover is not possible, the exposure of admin email addresses and other metadata increases the potential for phishing, credential stuffing, and social engineering attacks. An IDOR (Insecure Direct Object Reference) occurs when an application uses user-supplied input to directly access objects, such as files or database records, without proper authorization checks.
Recommendations Update to version 1.8.0-beta.27 or later.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-66306
GHSA-4CWQ-J7JV-QMWG

Affected Products

Grav Cms