Grav CMS IDOR Vulnerability in Admin Panel Allowing Unauthorized Access to Sensitive Information

Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability has been identified in the Grav CMS Admin Panel, prior to version 1.8.0-beta.27. This vulnerability allows low-privilege users to access sensitive information from other accounts. While it does not enable direct account takeover, it exposes admin email addresses and other metadata, increasing the risk of phishing, credential stuffing, and social engineering attacks.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive information, specifically admin email addresses and associated metadata, from other user accounts. This information can be leveraged for targeted phishing attacks, credential stuffing, or social engineering campaigns.

Reproduction

To reproduce this vulnerability, log in as a low-privilege user (an account with 0 privileges). Then, access the endpoint for another user account, such as '/admin/accounts/users/{username}'. Although a '403 Forbidden' response will be returned, the page source will reveal sensitive information, including the admin's email address, in the '<title>' tag.

Remediation

Users can upgrade to Grav version 1.8.0-beta.27 or later to address this vulnerability.

Added: Dec 1, 2025, 10:22 PM
Updated: Dec 1, 2025, 10:22 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
6.4
remediation
7.7
relevance
1.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.