Impact
Sandboxed Twig templates in Grav can call the offsetGet() and offsetexists() methods on User objects without proper filtering. Users with page‑edit permissions can use these calls to read sensitive fields such as hashed passwords and 2FA secrets, which can then be cracked offline or used to bypass authentication. The vulnerability therefore mainly threatens confidentiality and allows credential compromise.
Affected Systems
The flaw exists in Grav versions released before 2.0.16. All installations using getgrav:grav prior to that patch level are vulnerable when sandboxed Twig templates are enabled and page‑edit permissions are granted to potential attackers.
Risk and Exploitability
The CVSS score of 8.7 designates the weakness as high severity. EPSS data is not available, but the lack of mitigation and the capability to obtain hashed credentials make exploitation plausible. The attack requires a user with page‑edit rights and the ability to execute or add a qualified Twig template; it is not a remote code execution flaw. The vulnerability is not currently listed in the CISA KEV catalog, but the potential impact warrants prompt attention.
OpenCVE Enrichment