Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts. Although direct account takeover is not possible, admin email addresses and other metadata can be exposed, increasing the risk of phishing, credential stuffing, and social engineering. This vulnerability is fixed in 1.8.0-beta.27.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4cwq-j7jv-qmwg Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 02 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Getgrav
Getgrav grav
Vendors & Products Getgrav
Getgrav grav

Mon, 01 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
Description Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts. Although direct account takeover is not possible, admin email addresses and other metadata can be exposed, increasing the risk of phishing, credential stuffing, and social engineering. This vulnerability is fixed in 1.8.0-beta.27.
Title Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-02T20:11:28.148Z

Reserved: 2025-11-26T23:11:46.396Z

Link: CVE-2025-66306

cve-icon Vulnrichment

Updated: 2025-12-02T20:11:15.328Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-01T22:15:50.413

Modified: 2025-12-02T17:16:29.163

Link: CVE-2025-66306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-02T11:59:00Z