CVE-2025-66306: Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel

Published Dec 1, 2025
·
Updated

Summary

An IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel allows low-privilege users to access sensitive information from other accounts. Although direct account takeover is not possible, admin email addresses and other metadata can be exposed, increasing the risk of phishing, credential stuffing, and social engineering.

---

Details

Endpoint: /admin/accounts/users/{username} Tested Version: Grav Admin 1.7.48 Affected Accounts: Authenticated users with 0 privileges (non-privileged accounts)

Description: Requesting another user’s account details (e.g., /admin/accounts/users/admin) as a low-privilege user returns an HTTP 403 Forbidden response. However, sensitive information such as the admin’s email address is still present in the response source, specifically in the <title> tag.

system/src/Grav/Common/Flex/Types/Users/UserCollection.php <img width="700" height="327" alt="Screenshot 2025-08-24 021027" src="https://github.com/user-attachments/assets/7e69ae49-d8fc-442f-b00c-9efaec706b2e" />

system/blueprints/flex/user-accounts.yaml <img width="700" height="300" alt="Screenshot 2025-08-24 020521" src="https://github.com/user-attachments/assets/756631c8-d60b-4b84-a08a-2a9c2f81b41f" />

This is a classic IDOR vulnerability, where object references (usernames) are not properly protected from unauthorized enumeration.

---

PoC

1. Log in as a non-privileged user (0-privilege account). 2. Access another user’s endpoint, for example:

GET /admin/accounts/users/admin 3. Observe the HTTP 403 Forbidden response. 4. Inspect the page source; sensitive data such as the admin email can be seen in the <title> tag.

PoC Video:

https://drive.google.com/file/d/1lYqwqSkN5sPNmHvXGOk6R1mdIgVt71H/view

---

Impact

Type: Information Disclosure via IDOR Who is impacted: Low-privilege authenticated users can enumerate other accounts and extract sensitive metadata (admin emails). Risk: Exposed information can be used for targeted phishing, credential stuffing, brute-force attacks, or social engineering campaigns. Severity Justification: Only a low-privilege account is required, and sensitive metadata is leaked. Arbitrary code execution is not possible, but the information exposure is moderate risk.

---

Disclosure & CVE Request

We request a CVE ID for this vulnerability once validated. Please credit the discovery to:

Elvin Nuruyev Kanan Farzalili

Other sources

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts. Although direct account takeover is not possible, admin email addresses and other metadata can be exposed, increasing the risk of phishing, credential stuffing, and social engineering. This vulnerability is fixed in 1.8.0-beta.27.

MITRE

Affected Software

29 affected componentsFixes available
Grav Grav CMS<1.8.0-beta.27
composer/getgrav/grav<1.8.0-beta.27
1.8.0-beta.27
getgrav grav>=1.7.48<1.8.0
getgrav grav=1.8.0-beta1
getgrav grav=1.8.0-beta10
getgrav grav=1.8.0-beta11
getgrav grav=1.8.0-beta12
getgrav grav=1.8.0-beta13
getgrav grav=1.8.0-beta14
getgrav grav=1.8.0-beta15
getgrav grav=1.8.0-beta16
getgrav grav=1.8.0-beta17
getgrav grav=1.8.0-beta18
getgrav grav=1.8.0-beta19
getgrav grav=1.8.0-beta2
getgrav grav=1.8.0-beta20
getgrav grav=1.8.0-beta21
getgrav grav=1.8.0-beta22
getgrav grav=1.8.0-beta23
getgrav grav=1.8.0-beta24
getgrav grav=1.8.0-beta25
getgrav grav=1.8.0-beta26
getgrav grav=1.8.0-beta3
getgrav grav=1.8.0-beta4
getgrav grav=1.8.0-beta5
getgrav grav=1.8.0-beta6
getgrav grav=1.8.0-beta7
getgrav grav=1.8.0-beta8
getgrav grav=1.8.0-beta9

Event History

Dec 1, 2025
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 2, 2025
Advisory Published
via GitHub·12:39 AM
Data Sourced
via GitHub·12:39 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-66306?

CVE-2025-66306 has a significant severity level due to the potential exposure of sensitive information by low-privilege users.

2

How do I fix CVE-2025-66306?

To fix CVE-2025-66306, upgrade Grav CMS to version 1.8.0-beta.27 or later.

3

Who is affected by CVE-2025-66306?

CVE-2025-66306 affects Grav CMS versions prior to 1.8.0-beta.27.

4

What type of vulnerability is CVE-2025-66306?

CVE-2025-66306 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.

5

What potential impact does CVE-2025-66306 have?

CVE-2025-66306 allows low-privilege users to access sensitive information from other user accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203