Impact
The Grav Flex Objects plugin contains an authorization bypass that allows users with page‑edit rights to embed a special shortcode in any page. When processed, the shortcode renders the contents of any registered Flex collection, bypassing the ACL checks that normally restrict access. This enables the viewer to obtain directory listings and user account information that should be protected.
Affected Systems
The flaw affects Grav Flex Objects plugin versions 1.4.0 through 1.4.7. Attackers would need a Grav installation running one of these versions and a user who has page‑edit privileges. The vulnerability is limited to the Grav platform and its Flex Objects plugin.
Risk and Exploitability
With a CVSS score of 8.3, the vulnerability is considered high. The EPSS score is not available and the issue is not in the CISA KEV catalog. The likely attack path requires the attacker to add the problematic shortcode to a page that is publicly visible, so the potential for exploitation is mitigated if page‑edit rights are well protected or restricted to trusted users. Nevertheless, the absence of ACL checks during shortcode rendering makes the vulnerability exploitable whenever an edited page is delivered to a user.
OpenCVE Enrichment