Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-42610

3 месяца назад

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker can programmatically load administrative user objects and extract sensitive data, including Bcrypt password hashes and the security salt. This vulnerability is fixed in 2.0.0-beta.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f29-pqwf-v4j4

4 месяца назад

Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-42610

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker can programmatically load administrative user objects and extract sensitive data, including Bcrypt password hashes and the security salt. This vulnerability is fixed in 2.0.0-beta.2.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3f29-pqwf-v4j4

Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass

CVSS3: 6.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу