Aller au contenu

Fiche vulnérabilité

CVE-2025-66298 : faille élevée getgrav grav (CVSS 7.5)

Description

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side Template (SST) vulnerability. Sensitive information may be contained in the configuration details. This vulnerability is fixed in 1.8.0-beta.27.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
1 déc. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • getgrav grav

Références

Rechercher une autre vulnérabilité dans la base CVE