Количество 2
Количество 2
CVE-2026-42610
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker can programmatically load administrative user objects and extract sensitive data, including Bcrypt password hashes and the security salt. This vulnerability is fixed in 2.0.0-beta.2.
GHSA-3f29-pqwf-v4j4
Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-42610 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker can programmatically load administrative user objects and extract sensitive data, including Bcrypt password hashes and the security salt. This vulnerability is fixed in 2.0.0-beta.2. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-3f29-pqwf-v4j4 Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass | CVSS3: 6.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу