CVE-2025-66301: Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions

Published Dec 1, 2025
·
Updated

Summary Due to a broken access control vulnerability in the /admin/pages/{pagename} endpoint, an editor ( user with full permissions to pages ) can change the functionality of a form after submission.

Details Due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{pagename}, an editor with only permissions to change basic content on the form is now able to change the functioning of the form through modifying the content of the data[json][header][form] which is the YAML frontmatter which includes the process section which dictates what happens after a user submits the form which include some important actions that could lead to further vulnerabilities.

PoC

- Have Admin and Form plugins installed - Connect to panel as admin, create user and give him permission for pages all - Now connect as that user and notice you cant edit any process field in the panel - Change anything in the content of the form and save - Intercept the request: !image

- Now modify the field data[json][header][form] with the following payload URL-encoded not like this: {"name":"ssti-test 2","fields":{"name":{"type":"text","label":"Name","required":true}},"buttons":{"submit":{"type":"submit","value":"Submit"}},"process":[{"message":"{{ evaluatetwig(form.value('name')) }}"}]}

- Change the field and forward it: !image

Request goes through and changes have been made to the form. !image

Impact

- Attacker can modify submission logic of the form which leads to changing redirect value, email sending, changing template, breaking out of the Twig sandbox potentially executing code...

Fix recommendation

- Implement proper authorization checks to such requests especially when it contains fields user shouldn't be able to modify based on his role.

Other sources

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{pagename}, an editor with only permissions to change basic content on the form is now able to change the functioning of the form through modifying the content of the data[json][header][form] which is the YAML frontmatter which includes the process section which dictates what happens after a user submits the form which include some important actions that could lead to further vulnerabilities. This vulnerability is fixed in 1.8.0-beta.27.

MITRE

Affected Software

29 affected componentsFixes available
Grav Grav<1.8.0-beta.27
composer/getgrav/grav<1.8.0-beta.27
1.8.0-beta.27
getgrav grav<1.8.0
getgrav grav=1.8.0-beta1
getgrav grav=1.8.0-beta10
getgrav grav=1.8.0-beta11
getgrav grav=1.8.0-beta12
getgrav grav=1.8.0-beta13
getgrav grav=1.8.0-beta14
getgrav grav=1.8.0-beta15
getgrav grav=1.8.0-beta16
getgrav grav=1.8.0-beta17
getgrav grav=1.8.0-beta18
getgrav grav=1.8.0-beta19
getgrav grav=1.8.0-beta2
getgrav grav=1.8.0-beta20
getgrav grav=1.8.0-beta21
getgrav grav=1.8.0-beta22
getgrav grav=1.8.0-beta23
getgrav grav=1.8.0-beta24
getgrav grav=1.8.0-beta25
getgrav grav=1.8.0-beta26
getgrav grav=1.8.0-beta3
getgrav grav=1.8.0-beta4
getgrav grav=1.8.0-beta5
getgrav grav=1.8.0-beta6
getgrav grav=1.8.0-beta7
getgrav grav=1.8.0-beta8
getgrav grav=1.8.0-beta9

Event History

Dec 1, 2025
CVE Published
via MITRE·09:30 PM
Data Sourced
via MITRE·09:30 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Dec 2, 2025
Advisory Published
via GitHub·12:36 AM
Data Sourced
via GitHub·12:36 AM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-66301?

CVE-2025-66301 has been classified with a severity rating that indicates a potential for unauthorized modification of critical page fields.

2

How do I fix CVE-2025-66301?

To fix CVE-2025-66301, update Grav to version 1.8.0-beta.27 or later to ensure proper authorization checks are enforced.

3

What versions of Grav are affected by CVE-2025-66301?

CVE-2025-66301 affects all versions of Grav prior to 1.8.0-beta.27.

4

Can CVE-2025-66301 impact user data security?

Yes, CVE-2025-66301 can impact user data security by allowing unauthorized changes to critical content fields.

5

What specific actions are vulnerable in CVE-2025-66301?

CVE-2025-66301 allows editors to change functional parameters on POST requests to /admin/pages/{page_name}, which they should not have permission to modify.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203