Password Hash Exposure in Grav Web Platform
CVE-2025-66304
6.2MEDIUM
What is CVE-2025-66304?
Before version 1.8.0-beta.27, Grav's file-based Web platform allowed users with read access in the user account management section of the admin panel to view password hashes of all users, including administrators. This exposure of user password hashes could be exploited to achieve privilege escalation if an attacker successfully cracks these hashes, thus compromising the integrity and security of the entire system. The vulnerability has been addressed in the latest updates to ensure enhanced security for user data.
Affected Version(s)
grav < 1.8.0-beta.27
