File-Based Web Platform Vulnerability in Grav Affects User Accounts
CVE-2025-66300
What is CVE-2025-66300?
Grav is a file-based web platform that enables users to create and manage their websites efficiently. However, prior to version 1.8.0-beta.27, a vulnerability existed that allowed low privilege users with page editing rights to access sensitive server files. This included the ability to read Grav user account files, which contain critical information such as hashed passwords, 2FA secrets, and password reset tokens. An attacker could exploit this vulnerability to compromise any registered user's account by either obtaining the hashed password or the password reset token, leading to unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
grav < 1.8.0-beta.27
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
