Grav CMS 2.0.14 至 2.0.24 版本在用户组和账户的蓝图文档(blueprints)中存在权限提升漏洞。访问控制映射由一个 守卫(guard)机制进行限制,该守卫通过字段的精确路径进行解析。然而,当提交采用平面点表示法(flat dot-notation)的键,例如 (而非嵌套形式的 )时,不会匹配任何蓝图文档规则,从而能够绕过 BlueprintSchema::filterArray() 的过滤和展平操作,并最终由 FlexObject::update() 通过 setNestedPropert
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100673 | 8.2 HIGH | Grav Data Manager before 1.4.5 Stored XSS via item-detail view |
| CVE-2026-100671 | 8.0 HIGH | Grav before 2.0.25 Session Cookie Theft via Twig Sandbox |
| CVE-2026-100669 | 7.5 HIGH | Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass |
| CVE-2026-100672 | 7.5 HIGH | grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure |
| CVE-2026-100668 | 6.5 MEDIUM | Grav before 2.0.25 Sandbox Escape via array Filter |
| CVE-2026-100667 | 5.3 MEDIUM | grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass |
No comments yet