User Enumeration and Email Disclosure in Grav Admin Plugin
CVE-2025-66307
6.5MEDIUM
What is CVE-2025-66307?
The Grav Admin Plugin presents a vulnerability that allows attackers to exploit the 'Forgot Password' feature, disclosing valid usernames and their associated email addresses through different server responses. This flaw enables user enumeration, which can be exploited to carry out targeted attacks like password spraying and phishing. It is essential for users of the Grav Admin Plugin to upgrade to version 1.11.0-beta.1 or later to mitigate these risks.
Affected Version(s)
grav < 1.11.0-beta.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
