Grav Grav-plugin-api Bypass of Authorization (CWE-639) via createApiKey and 2FA Stripping (CVE-2024-8266)
Security Advisory
CVE-2024-8266
Critical
Grav
Affected:
- getgrav/grav-plugin-api <= 1.0.5
Fixed in:
- 1.0.6
Referenced CVEs:
CVE-2026-62666 · 8.8
CVE-2026-62233 · 8.8
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.