Impact
Grav versions earlier than 1.6.30 contain a cross‑site scripting flaw in the default Admin plugin page editor. The default security configuration fails to sanitise user‑supplied content, allowing a user who has page‑editing rights to inject arbitrary JavaScript. When that script runs in a privileged context it can be used to install malicious plugins or execute other arbitrary code, leading to full system compromise.
Affected Systems
The vulnerability affects the Grav Admin plugin for all releases prior to 1.6.30. Users running Grav with page‑editing permissions on those older versions are susceptible to exploitation.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. With no EPSS score available the likelihood of exploitation is unknown, and the vulnerability is not listed in CISA’s KEV catalog. However, exploitation requires authenticated privileged access; an attacker can inject code that runs with the same permissions as the editor, potentially gaining full administrative control of the Grav installation.
OpenCVE Enrichment