grav-plugin-api 在 1.0.20 之前的版本中存在一个权限提升漏洞,位于 InvitationsController 中。该漏洞源于 stripSuperFlags() 方法仅能移除嵌套的 super 标志,却未能移除以点号作为键的等价标志(如 api.super)。因此,拥有 api.access 和 api.users.write 权限的非超级用户管理员可以创建一个包含点号键超级标志(如 api.super)的邀请请求,从而绕过检查机制,并将该标志持久化到新创建的账户中。攻击者随后可以通过公共端
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| getgrav | grav-plugin-api | < 1.0.20 |
affected |
1.0.20 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getgrav | grav-plugin-api | 0 ~ 1.0.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86196 | 8.7 HIGH | Grav API Plugin before 1.0.20 Authentication Bypass via Host Header |
| CVE-2026-86193 | 8.7 HIGH | Grav API Plugin Authentication Bypass via Group-Inherited Super |
| CVE-2026-86194 | 6.9 MEDIUM | Grav Form Plugin before 9.1.22 Cross-Page Form Execution |
| CVE-2026-86197 | 5.1 MEDIUM | Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox |
No comments yet