CVE-2025-66300

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includes Grav user account files (/grav/user/accounts/*.yaml), which store hashed user password, 2FA secret, and the password reset token. This can allow an adversary to compromise any registered account by resetting a password for a user to get access to the password reset token from the file or by cracking the hashed password. This vulnerability is fixed in 1.8.0-beta.27.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
GitHub_MCNA
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
getgravgrav
𝑥
< 1.8.0
getgravgrav
1.8.0:beta1
getgravgrav
1.8.0:beta10
getgravgrav
1.8.0:beta11
getgravgrav
1.8.0:beta12
getgravgrav
1.8.0:beta13
getgravgrav
1.8.0:beta14
getgravgrav
1.8.0:beta15
getgravgrav
1.8.0:beta16
getgravgrav
1.8.0:beta17
getgravgrav
1.8.0:beta18
getgravgrav
1.8.0:beta19
getgravgrav
1.8.0:beta2
getgravgrav
1.8.0:beta20
getgravgrav
1.8.0:beta21
getgravgrav
1.8.0:beta22
getgravgrav
1.8.0:beta23
getgravgrav
1.8.0:beta24
getgravgrav
1.8.0:beta25
getgravgrav
1.8.0:beta26
getgravgrav
1.8.0:beta3
getgravgrav
1.8.0:beta4
getgravgrav
1.8.0:beta5
getgravgrav
1.8.0:beta6
getgravgrav
1.8.0:beta7
getgravgrav
1.8.0:beta8
getgravgrav
1.8.0:beta9
𝑥
= Vulnerable software versions