Impact
The Grav API Plugin before version 1.0.20 allows a non‑super user manager to bypass permission validation on accounts that inherit super rights through a group. An attacker who has api.access and api.users.write permissions can patch the password field of any group‑super account, effectively taking full administrative control of the site. This weakness leads to a loss of confidentiality, integrity, and availability of the administrative functions of Grav, as unauthorized users can assume a super‑admin identity.
Affected Systems
The vulnerability affects the Grav API Plugin distributed by Getgrav, specifically versions prior to 1.0.20. Systems running the vulnerable plugin combination are at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity of the flaw. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is through the API: an attacker must possess api.access and api.users.write scopes. Once these scopes are obtained, the exploit is trivial, as no additional authentication or privilege escalation steps are required beyond the legitimate API permissions.
OpenCVE Enrichment