Impact
A flaw in the Grav CMS allows attackers to access the Clockwork profiler endpoint without authentication when the system debugger is enabled. The endpoint returns all stored debugging data, including raw request cookies that contain the PHP session ID, the full request body with unfiltered credentials, and the site configuration with secrets such as SMTP and API keys. Because the profiler does not enforce any user lookup, IP restriction, or authenticator check, any web client can query the data and obtain sensitive information that could be reused to impersonate another user or compromise the site.
Affected Systems
The issue affects Grav CMS versions from 1.7.0 through 1.7.53.2 and from 2.0.0 through 2.0.21. This includes all installations of the Grav flat-file CMS where the debugger feature is enabled in the configuration. The vulnerability is identified by the vendor getgrav for the product Grav.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity, and its EPSS score is currently unavailable but the lack of authentication makes exploitation straightforward. The vulnerability is not yet listed in CISA’s KEV catalog. An attacker can exploit it by sending a request to /__clockwork/ while the debugger is enabled, retrieving the entire debugging history, and using the captured session id to hijack an admin session or expose plaintext passwords and configuration secrets.
OpenCVE Enrichment