Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-42610

Опубликовано: 11 мая 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker can programmatically load administrative user objects and extract sensitive data, including Bcrypt password hashes and the security salt. This vulnerability is fixed in 2.0.0-beta.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
Версия до 1.8.0 (включая)
cpe:2.3:a:getgrav:grav:2.0.0:beta1:*:*:*:*:*:*

EPSS

Процентиль: 22%
0.0029
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
github
4 месяца назад

Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass

EPSS

Процентиль: 22%
0.0029
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863