Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update
Vulnerability Description
The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the registration handler, this handler does not strip privilege fields ('groups','access') from user-submitted form data before persisting them. When an administrator has added 'groups' and/or 'access' to plugins.login.user_registration.fields and the default 'regular'/DataUser account backend is in use, a low-privilege authenticated user can POST crafted profile form data (e.g. access[admin][super]=true) to escalate to super-admin, enabling admin panel access, scheduler abuse (RCE), and Twig evaluation. Fixed in 3.8.12.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
Grav 权限许可和访问控制问题漏洞
Vulnerability Description
Grav Grav是Grav组织开源的一个基于文件系统的无数据库内容管理系统。 Grav 3.8.11及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于经过身份验证的配置文件自更新处理程序(processUserProfile(),update_user任务)在持久化用户提交的表单数据之前未剥离权限字段('groups','access'),可能导致低权限经过身份验证的用户通过特制的配置文件表单数据(例如access[admin][super]=true)提升权限至超级管理员。
CVSS Information
N/A
Vulnerability Type
N/A