User Enumeration and Email Disclosure in Grav Admin Plugin
CVE-2025-66307

6.5MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
1 December 2025

What is CVE-2025-66307?

The Grav Admin Plugin presents a vulnerability that allows attackers to exploit the 'Forgot Password' feature, disclosing valid usernames and their associated email addresses through different server responses. This flaw enables user enumeration, which can be exploited to carry out targeted attacks like password spraying and phishing. It is essential for users of the Grav Admin Plugin to upgrade to version 1.11.0-beta.1 or later to mitigate these risks.

Affected Version(s)

grav < 1.11.0-beta.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.